Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2009-3114

EPSS 0.77% · P74
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2009-3114

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
The RSS reader widget in IBM Lotus Notes 8.0 and 8.5 saves items from an RSS feed as local HTML documents, which allows remote attackers to execute arbitrary script in Internet Explorer's Local Machine Zone via a crafted feed, aka SPR RGAU7RDJ9K.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
IBM Lotus Notes RSS阅读器HTML注入漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
IBM Lotus Notes是由IBM开发的集成邮件、日历、即时消息、浏览器和业务协作应用,可用作Lotus Domino服务器应用的桌面客户端。 IBM Lotus Notes提供了一些可由用户选择添加和启用的小工具,其中一个工具是RSS阅读器。这个阅读器下载RSS文件、获取其中的项并本地保存为HTML文件。由于本地保存的文件在Internet Explorer中是以本地Intranet区运行的,因此在解释和显示RSS项时会导致以提升的权限运行其中注入的脚本。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2009-3114

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2009-3114

登录查看更多情报信息。

Same Patch Batch · n/a · 2009-09-09 · 24 CVEs total

CVE-2008-7192WoltLab Burning Board 脚本index.php 跨站请求伪造漏洞
CVE-2009-2266oxid eshop 敏感信息泄露漏洞
CVE-2008-7191Pps.Jussieu Polipo未明漏洞
CVE-2008-7190Adium 未明漏洞
CVE-2008-7189Bastian_Blumentritt Local Media Browser 多个未明漏洞
CVE-2008-7188ClipShare 'siteadmin/useredit.php' 权限限制和访问控制漏洞
CVE-2008-7187Coppermine Photo Gallery 脚本include/slideshow.inc.php信息泄露漏洞
CVE-2008-7186Coppermine Photo Gallery 'update.php' 权限许可和访问控制漏洞
CVE-2009-3111FreeRADIUS src/lib/radius.c 'rad_decode()'拒绝服务漏洞
CVE-2009-3113OXID eShop 未明漏洞
CVE-2009-3112Oxidforge OXID eShop未明安全漏洞
CVE-2008-7193PHPKIT 跨站请求伪造漏洞
CVE-2009-2205Apple Java Update 'Java Web Start'缓冲区溢出漏洞
CVE-2009-3124Ipmotor QuarkMail 'get_message.cgi'路径遍历漏洞
CVE-2009-3123Visavi Wap-Motor gallery/gallery.php路径遍历漏洞
CVE-2009-3122Drupal Ajax Table权限许可和访问控制漏洞
CVE-2009-3121Drupal Ajax Table跨站脚本攻击漏洞
CVE-2009-3120BIGACE Web CMS 'public/index.php'跨站脚本攻击漏洞
CVE-2009-3119X-Iweb.Ru Download System mSF SQL注入漏洞
CVE-2009-3118Danneo CMS 'mod/poll/comment.php' SQL注入漏洞

Showing top 20 of 24 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2009-3114

No comments yet


Leave a comment