Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2009-0417

Cross-site scripting (XSS) vulnerability in the AgaviWebRouting::gen(null) method in Agavi 0.11 before 0.11.6 and 1.0 before 1.0.0 beta 8 allows remote attackers to inject arbitrary web script or HTML via a crafted URL with certain characters that are not properly handled by web browsers that do not strictly follow RFC 3986, such as Internet Explorer 6 and 7.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 53.6%
CVSS Severity
CVSS v2 Score 4.3
Products affected by CVE-2009-0417
  • Agavi » Agavi » Version: 0.11.0
    cpe:2.3:a:agavi:agavi:0.11.0
  • Agavi » Agavi » Version: 0.11.1
    cpe:2.3:a:agavi:agavi:0.11.1
  • Agavi » Agavi » Version: 0.11.2
    cpe:2.3:a:agavi:agavi:0.11.2
  • Agavi » Agavi » Version: 0.11.3
    cpe:2.3:a:agavi:agavi:0.11.3
  • Agavi » Agavi » Version: 0.11.4
    cpe:2.3:a:agavi:agavi:0.11.4
  • Agavi » Agavi » Version: 0.11.5
    cpe:2.3:a:agavi:agavi:0.11.5
  • Agavi » Agavi » Version: 0.11.6
    cpe:2.3:a:agavi:agavi:0.11.6
  • Agavi » Agavi » Version: 1.0.0
    cpe:2.3:a:agavi:agavi:1.0.0


Contact Us

Shodan ® - All rights reserved