CVE-2009-3730
IBM Rational RequisitePro 7.1.0 - Cross-Site Scripting via ReqWeb Help Parameters
Title source: llmExploitation Summary
EIP tracks 3 public exploits for CVE-2009-3730. PoCs published by IBM.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in ReqWebHelp by crafting malicious URIs that inject JavaScript code. The PoC includes example URIs that trigger alert pop-ups, confirming the vulnerability.
Description
Multiple cross-site scripting (XSS) vulnerabilities in the ReqWeb Help feature (aka the Web Client Help system) in IBM Rational RequisitePro 7.1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the operation parameter to ReqWebHelp/advanced/workingSet.jsp, or the (2) searchWord, (3) maxHits, (4) scopedSearch, or (5) scope parameter to ReqWebHelp/basic/searchView.jsp.
Exploits (3)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in ReqWebHelp by crafting malicious URIs that inject JavaScript code. The PoC includes example URIs that trigger alert pop-ups, confirming the vulnerability.
This exploit demonstrates a cross-site scripting (XSS) vulnerability in IBM Rational RequisitePro by injecting arbitrary JavaScript code via unsanitized input parameters in the searchView.jsp page. The PoC uses script tags to trigger an alert dialog, proving the vulnerability.
This exploit demonstrates a cross-site scripting (XSS) vulnerability in IBM Rational RequisitePro by injecting arbitrary JavaScript code via the 'operation' parameter in the URL. The PoC triggers an alert dialog, proving the vulnerability exists.