CVE-2009-3789

Opendocman - XSS

Title source: rule

Description

Multiple cross-site scripting (XSS) vulnerabilities in OpenDocMan 1.2.5 allow remote attackers to inject arbitrary web script or HTML via the last_message parameter to (1) add.php, (2) toBePublished.php, (3) index.php, and (4) admin.php; the PATH_INFO to the default URI to (5) category.php, (6) department.php, (7) profile.php, (8) rejects.php, (9) search.php, (10) toBePublished.php, (11) user.php, and (12) view_file.php; and (13) the caller parameter in a Modify User action to user.php.

Exploits (12)

exploitdb WORKING POC VERIFIED
by Amol Naik · textwebappsphp
https://www.exploit-db.com/exploits/33304
exploitdb WRITEUP VERIFIED
by Amol Naik · textwebappsphp
https://www.exploit-db.com/exploits/33305
exploitdb WRITEUP VERIFIED
by Amol Naik · textwebappsphp
https://www.exploit-db.com/exploits/9903
exploitdb WORKING POC VERIFIED
by Amol Naik · textwebappsphp
https://www.exploit-db.com/exploits/33300
exploitdb WRITEUP VERIFIED
by Amol Naik · textwebappsphp
https://www.exploit-db.com/exploits/33301
exploitdb WRITEUP VERIFIED
by Amol Naik · textwebappsphp
https://www.exploit-db.com/exploits/33302
exploitdb WRITEUP VERIFIED
by Amol Naik · textwebappsphp
https://www.exploit-db.com/exploits/33303
exploitdb WRITEUP VERIFIED
by Amol Naik · textwebappsphp
https://www.exploit-db.com/exploits/33296
exploitdb WRITEUP VERIFIED
by Amol Naik · textwebappsphp
https://www.exploit-db.com/exploits/33295
exploitdb WRITEUP VERIFIED
by Amol Naik · textwebappsphp
https://www.exploit-db.com/exploits/33298
exploitdb WORKING POC VERIFIED
by Amol Naik · textwebappsphp
https://www.exploit-db.com/exploits/33299
exploitdb WRITEUP VERIFIED
by Amol Naik · textwebappsphp
https://www.exploit-db.com/exploits/33297

Scores

EPSS 0.0260
EPSS Percentile 85.4%

Classification

CWE
CWE-79
Status published

Affected Products (2)

opendocman/opendocman
n/a/n/a

Timeline

Published Oct 26, 2009
Tracked Since Feb 18, 2026