CVE-2009-3029

Symantec Securityexpressions Audit And Compliance Server < 4.1.1 - XSS

Title source: rule

Description

Cross-site scripting (XSS) vulnerability in the console in Symantec SecurityExpressions Audit and Compliance Server 4.1.1, 4.1, and earlier allows remote authenticated users to inject arbitrary web script or HTML via "external client input" that triggers crafted error messages.

Scores

EPSS 0.0051
EPSS Percentile 65.9%

Classification

CWE
CWE-79
Status published

Affected Products (3)

symantec/securityexpressions_audit_and_compliance_server < 4.1.1
symantec/securityexpressions_audit_and_compliance_server
n/a/n/a

Timeline

Published Oct 15, 2009
Tracked Since Feb 18, 2026