Description
Multiple cross-site scripting (XSS) vulnerabilities on the Network Management Card (NMC) on American Power Conversion (APC) Switched Rack PDU (aka Rack Mount Power Distribution) devices and other devices allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: the login_username vector for Forms/login1 is already covered by CVE-2009-4406.
Exploits (1)
exploitdb
WRITEUP
VERIFIED
by Jamal Pecou · textremotemultiple
https://www.exploit-db.com/exploits/33405
References (4)
Core 4
Core References
Various Sources x_refsource_misc
http://holisticinfosec.org/content/view/111/45/
Vendor Advisory x_refsource_confirm
http://nam-en.apc.com/cgi-bin/nam_en.cfg/php/enduser/std_adp.php?p_faqid=10887
US Government Resource third-party-advisory
x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/166739
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/37744
Scores
EPSS
0.0415
EPSS Percentile
88.8%
Details
CWE
CWE-79
Status
published
Products (2)
apc/network_management_card
apc/switched_rack_pdu
Published
Dec 28, 2009
Tracked Since
Feb 18, 2026