CVE-2009-1294

Novell Teaming 1.0-1.0.3 - Cross-Site Scripting via p_p_state or p_p_mode Parameters

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2009-1294. PoCs published by Michael Kirchner.

AI-analyzed exploit summary The provided text describes a user-enumeration weakness and multiple XSS vulnerabilities in Novell Teaming 1.0.3. It includes a sample URL demonstrating an XSS attack via the 'p_p_state' parameter.

Description

Multiple cross-site scripting (XSS) vulnerabilities in web/guest/home in the Liferay 4.3.0 portal in Novell Teaming 1.0 through SP3 (1.0.3) allow remote attackers to inject arbitrary web script or HTML via the (1) p_p_state or (2) p_p_mode parameters.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Michael Kirchner · textwebappsjava
https://www.exploit-db.com/exploits/32909

The provided text describes a user-enumeration weakness and multiple XSS vulnerabilities in Novell Teaming 1.0.3. It includes a sample URL demonstrating an XSS attack via the 'p_p_state' parameter.

Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Novell Teaming 1.0.3
No auth needed
Prerequisites: Access to the target web application
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2009/1048
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/34714
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/502704/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1022063
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/34531

Scores

EPSS 0.0256
EPSS Percentile 85.7%

Details

CWE
CWE-79
Status published
Products (5)
liferay/liferay_enterprise_portal 4.3.0
novell/teaming 1.0
novell/teaming 1.0.1
novell/teaming 1.0.2
novell/teaming 1.0.3
Published Apr 16, 2009
Tracked Since Feb 18, 2026