CVE-2009-0917
Dflabs Ptk - XSS
Title source: ruleDescription
Cross-site scripting (XSS) vulnerability in DFLabs PTK 1.0.0 through 1.0.4 allows remote attackers to inject arbitrary web script or HTML by providing a forensic image containing HTML documents, which are rendered in web browsers during inspection by PTK. NOTE: the vendor states that the product is intended for use in a laboratory with "no contact from / to internet."
References (7)
Scores
EPSS
0.0225
EPSS Percentile
84.4%
Classification
CWE
CWE-79
Status
published
Affected Products (6)
dflabs/ptk
dflabs/ptk
dflabs/ptk
dflabs/ptk
dflabs/ptk
n/a/n/a
Timeline
Published
Mar 16, 2009
Tracked Since
Feb 18, 2026