CVE-2009-1294
Novell Teaming 1.0-1.0.3 - Cross-Site Scripting via p_p_state or p_p_mode Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-1294. PoCs published by Michael Kirchner.
AI-analyzed exploit summary The provided text describes a user-enumeration weakness and multiple XSS vulnerabilities in Novell Teaming 1.0.3. It includes a sample URL demonstrating an XSS attack via the 'p_p_state' parameter.
Description
Multiple cross-site scripting (XSS) vulnerabilities in web/guest/home in the Liferay 4.3.0 portal in Novell Teaming 1.0 through SP3 (1.0.3) allow remote attackers to inject arbitrary web script or HTML via the (1) p_p_state or (2) p_p_mode parameters.
Exploits (1)
The provided text describes a user-enumeration weakness and multiple XSS vulnerabilities in Novell Teaming 1.0.3. It includes a sample URL demonstrating an XSS attack via the 'p_p_state' parameter.