MEDIUM
ejabberd: XSS vulnerability
Published Mar 18, 2009
4.3
MEDIUMCVSS 2.0
EPSS 1.60%
Description
Cross-site scripting (XSS) vulnerability in ejabberd before 2.0.4 allows remote attackers to inject arbitrary web script or HTML via unknown vectors related to links and MUC logs.
Affected products
No data.
OR
- ≤ 2.0.3
- 0.9
- 0.9.1
- 0.9.8
- 1.0.0
- 1.1.0
- 1.1.1
- 1.1.1.0
- 1.1.1.1
- 1.1.2
- 1.1.3
- 1.1.14
- 2.0.0
- 2.0.0
- 2.0.0
- 2.0.1_2
- 2.0.2
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (16)
- http://osvdb.org/52714 vdb-entryx_refsource_OSVDB
- http://secunia.com/advisories/34340 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/34354 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/34781 third-party-advisoryx_refsource_SECUNIA
- http://www.debian.org/security/2009/dsa-1774 vendor-advisoryx_refsource_DEBIAN
- http://www.openwall.com/lists/oss-security/2009/03/16/1 mailing-listx_refsource_MLIST
- http://www.process-one.net/en/ejabberd/release_notes/release_note_ejabberd_204 x_refsource_CONFIRMVendor Advisory
- http://www.securityfocus.com/bid/34133 vdb-entryx_refsource_BID
- https://access.redhat.com/security/cve/CVE-2009-0934 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=490902 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2009-0931 Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/49289 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2009-0934
- https://www.cve.org/CVERecord?id=CVE-2009-0934
- https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00675.html vendor-advisoryx_refsource_FEDORA
- https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00735.html vendor-advisoryx_refsource_FEDORA
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Mar 18, 2009
Updated Aug 7, 2024
Reserved Mar 17, 2009
Link CVE-2009-0934
CISA Vulnrichment
No data
GitHub
No data