CVE-2009-1593
Armorlogic Profense WAF <2.2.22 & 2.4.x<2.4.4 XSS via SCRIPT Tag
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-1593. PoCs published by EnableSecurity.
AI-analyzed exploit summary The provided text describes a security bypass vulnerability in Profense Web Application Firewall, allowing attackers to bypass restrictions and perform web attacks. It includes example URLs demonstrating XSS payloads that exploit the vulnerability.
Description
Armorlogic Profense Web Application Firewall before 2.2.22, and 2.4.x before 2.4.4, does not properly implement the "negative model," which allows remote attackers to conduct cross-site scripting (XSS) attacks via a modified end tag of a SCRIPT element.
Exploits (1)
The provided text describes a security bypass vulnerability in Profense Web Application Firewall, allowing attackers to bypass restrictions and perform web attacks. It includes example URLs demonstrating XSS payloads that exploit the vulnerability.