CVE-2009-1294
Novell Teaming - XSS
Title source: ruleDescription
Multiple cross-site scripting (XSS) vulnerabilities in web/guest/home in the Liferay 4.3.0 portal in Novell Teaming 1.0 through SP3 (1.0.3) allow remote attackers to inject arbitrary web script or HTML via the (1) p_p_state or (2) p_p_mode parameters.
Exploits (1)
exploitdb
WRITEUP
VERIFIED
by Michael Kirchner · textwebappsjava
https://www.exploit-db.com/exploits/32909
References (7)
Scores
EPSS
0.0245
EPSS Percentile
85.0%
Classification
CWE
CWE-79
Status
published
Affected Products (6)
novell/teaming
novell/teaming
novell/teaming
novell/teaming
liferay/liferay_enterprise_portal
n/a/n/a
Timeline
Published
Apr 16, 2009
Tracked Since
Feb 18, 2026