37035Third-party advisory
http://secunia.com/advisories/37035 CVE-2009-2733
Achievo 1.x - Multiple Cross-Site Scripting / HTML Injection Vulnerabilities
Record summary
CVE-2009-2733 has a selected CVSS score of 4.3; EIP currently links 2 catalogued exploits.
Description
Multiple cross-site scripting (XSS) vulnerabilities in Achievo before 1.4.0 allow remote attackers to inject arbitrary web script or HTML via (1) the scheduler title in the scheduler module, and the (2) atksearch[contractnumber], (3) atksearch_AE_customer[customer], (4) atksearchmode[contracttype], and possibly (5) atksearch[contractname] parameters to the Organization Contracts administration page, reachable through dispatch.php.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 2
Proofs of concept
2Catalogued exploits
ExploitDBAchievo 1.x - Multiple Cross-Site Scripting / HTML Injection VulnerabilitiesExploitDB exploitby Ryan DewhurstNot analyzed1 file
ExploitDBAchievo 1.3.4 - Cross-Site ScriptingExploitDB exploitby Ryan DewhurstNot analyzed1 file
References
101023017vdb entry
http://securitytracker.com/id?1023017 achievo.orgConfirmation
http://www.achievo.org/download/releasenotes/1_4_0 bonsai-sec.com
http://www.bonsai-sec.com/blog/index.php/cross-site-scripting-payloads bonsai-sec.com
http://www.bonsai-sec.com/research/vulnerabilities/achievo-multiple-xss-0101.txt 20091013 [BONSAI] XSS in Achievo - Customized XSS payload includedmailing list
http://www.securityfocus.com/archive/1/507133/100/0/threaded 36661vdb entry
http://www.securityfocus.com/bid/36661 achievo-title-xss(53744)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/53744 achievo-dispatchphp-xss(53745)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/53745 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2009-2733