Vulnerability Description
The cross-site scripting (XSS) protection mechanism in ShowInContentAreaAction.do in ManageEngine Password Manager Pro (PMP) before 6.1 Build 6104 uses case-sensitive checks for malicious inputs, which allows remote attackers to inject arbitrary web script or HTML via the searchtext parameter and other unspecified inputs.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Manageengine | Password Manager Pro | <= 6.1 |
| Manageengine | Password Manager Pro6.1 | <= - |
Related Weaknesses (CWE)
References
- http://forums.manageengine.com/#Topic/49000003740390
- http://secunia.com/advisories/37765Vendor Advisory
- http://www.manageengine.com/products/passwordmanagerpro/release-notes.htmlPatch
- http://www.scip.ch/?vuldb.4063Patch
- http://www.scip.ch/publikationen/advisories/scip_advisory-4063_manageengine_pmp_Exploit
- http://www.securityfocus.com/bid/37336
- http://www.vupen.com/english/advisories/2009/3540PatchVendor Advisory
- http://forums.manageengine.com/#Topic/49000003740390
- http://secunia.com/advisories/37765Vendor Advisory
- http://www.manageengine.com/products/passwordmanagerpro/release-notes.htmlPatch
- http://www.scip.ch/?vuldb.4063Patch
- http://www.scip.ch/publikationen/advisories/scip_advisory-4063_manageengine_pmp_Exploit
- http://www.securityfocus.com/bid/37336
- http://www.vupen.com/english/advisories/2009/3540PatchVendor Advisory
FAQ
What is CVE-2009-4387?
CVE-2009-4387 is a vulnerability with a CVSS score of 4.3 (MEDIUM). The cross-site scripting (XSS) protection mechanism in ShowInContentAreaAction.do in ManageEngine Password Manager Pro (PMP) before 6.1 Build 6104 uses case-sensitive checks for malicious inputs, whic...
How severe is CVE-2009-4387?
CVE-2009-4387 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2009-4387?
Check the references section above for vendor advisories and patch information. Affected products include: Manageengine Password Manager Pro, Manageengine Password Manager Pro6.1.