CVE-2009-3036

Symantec IM Manager - XSS

Title source: rule

Description

Cross-site scripting (XSS) vulnerability in the console in Symantec IM Manager 8.3 and 8.4 before 8.4.13 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Exploits (1)

nomisec WRITEUP
by brinhosa · poc
https://github.com/brinhosa/CVE-2009-3036

Scores

EPSS 0.0075
EPSS Percentile 73.0%

Classification

CWE
CWE-79
Status published

Affected Products (3)

symantec/im_manager
symantec/im_manager
n/a/n/a

Timeline

Published Feb 23, 2010
Tracked Since Feb 18, 2026