CVE-2009-2733

Achievo <1.4.0 - XSS

Title source: llm
STIX 2.1

Description

Multiple cross-site scripting (XSS) vulnerabilities in Achievo before 1.4.0 allow remote attackers to inject arbitrary web script or HTML via (1) the scheduler title in the scheduler module, and the (2) atksearch[contractnumber], (3) atksearch_AE_customer[customer], (4) atksearchmode[contracttype], and possibly (5) atksearch[contractname] parameters to the Organization Contracts administration page, reachable through dispatch.php.

Exploits (2)

exploitdb WRITEUP VERIFIED
by Ryan Dewhurst · textwebappsphp
https://www.exploit-db.com/exploits/9863
exploitdb WORKING POC VERIFIED
by Ryan Dewhurst · textwebappsphp
https://www.exploit-db.com/exploits/33281

References (9)

Core 9
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/53745
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/53744
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/37035
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1023017
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/36661
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/507133/100/0/threaded

Scores

EPSS 0.0547
EPSS Percentile 90.2%

Details

CWE
CWE-79
Status published
Products (23)
achievo/achievo 0.7.0
achievo/achievo 0.7.1
achievo/achievo 0.7.2
achievo/achievo 0.7.3
achievo/achievo 0.8.0
achievo/achievo 0.8.0_rc1
achievo/achievo 0.8.0_rc2
achievo/achievo 0.8.1
achievo/achievo 0.9.0
achievo/achievo 0.9.1
... and 13 more
Published Oct 16, 2009
Tracked Since Feb 18, 2026