CVE-2009-0417

Cross-site scripting (XSS) vulnerability in the AgaviWebRouting::gen(null) method in Agavi 0.11 before 0.11.6 and 1.0 before 1.0.0 beta 8 allows remote attackers to inject arbitrary web script or HTML via a crafted URL with certain characters that are not properly handled by web browsers that do not strictly follow RFC 3986, such as Internet Explorer 6 and 7.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 53%
VendorProductVersion
agaviagavi
0.11.0
agaviagavi
0.11.0:rc1
agaviagavi
0.11.0:rc2
agaviagavi
0.11.0:rc3
agaviagavi
0.11.0:rc4
agaviagavi
0.11.0:rc5
agaviagavi
0.11.0:rc6
agaviagavi
0.11.0:rc7
agaviagavi
0.11.1
agaviagavi
0.11.1:rc1
agaviagavi
0.11.1:rc2
agaviagavi
0.11.1:rc3
agaviagavi
0.11.2
agaviagavi
0.11.2:rc1
agaviagavi
0.11.2:rc2
agaviagavi
0.11.3
agaviagavi
0.11.3:rc1
agaviagavi
0.11.3:rc2
agaviagavi
0.11.4
agaviagavi
0.11.4:rc1
agaviagavi
0.11.5
agaviagavi
0.11.5:rc1
agaviagavi
0.11.6
agaviagavi
0.11.6:rc1
agaviagavi
0.11.6:rc2
agaviagavi
1.0.0:beta1
agaviagavi
1.0.0:beta2
agaviagavi
1.0.0:beta3
agaviagavi
1.0.0:beta4
agaviagavi
1.0.0:beta5
agaviagavi
1.0.0:beta6
agaviagavi
1.0.0:beta7
𝑥
= Vulnerable software versions