CVE-2009-3487
Last modified
CVE-2009-3487 is a vulnerability of currently unknown severity. Multiple cross-site scripting (XSS) vulnerabilities in the J-Web interface in Juniper JUNOS 8.5R1.14 allow remote authenticated users to inject arbitrary web script or HTML via (1) the JEXEC_OUTID parameter in a JEXEC_MODE_RELAY_OUTPUT action to the jexec program; the (2) act, (3) refresh-time, or (4) ifid parameter to scripter.php; (5) the revision parameter in a rollback action to the configuration program; the m[] parameter to the (6) monitor, (7) manage, (8) events, (9) configuration, or (10) alarms program; (11) the m[] parameter to the default URI; (12) the m[] parameter in a browse action to the default URI; (13) the wizard-next parameter in an https action to the configuration program; or the (14) Contact Information, (15) System Description, (16) Local Engine ID, (17) System Location, or (18) System Name Override SNMP parameter, related to the configuration program.. EPSS estimates a 1.25% chance of exploitation in the next 30 days.
Description
Multiple cross-site scripting (XSS) vulnerabilities in the J-Web interface in Juniper JUNOS 8.5R1.14 allow remote authenticated users to inject arbitrary web script or HTML via (1) the JEXEC_OUTID parameter in a JEXEC_MODE_RELAY_OUTPUT action to the jexec program; the (2) act, (3) refresh-time, or (4) ifid parameter to scripter.php; (5) the revision parameter in a rollback action to the configuration program; the m[] parameter to the (6) monitor, (7) manage, (8) events, (9) configuration, or (10) alarms program; (11) the m[] parameter to the default URI; (12) the m[] parameter in a browse action to the default URI; (13) the wizard-next parameter in an https action to the configuration program; or the (14) Contact Information, (15) System Description, (16) Local Engine ID, (17) System Location, or (18) System Name Override SNMP parameter, related to the configuration program.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Juniper | Junos | 8.5 | R1.14 |
References
- http://secunia.com/advisories/36829Exploit, Vendor Advisory
- http://www.vupen.com/english/advisories/2009/2784Vendor Advisory
- http://secunia.com/advisories/36829Exploit, Vendor Advisory
- http://www.vupen.com/english/advisories/2009/2784Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2009-3487?
How severe is CVE-2009-3487?
How do I fix CVE-2009-3487?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2009
- CVE-2009-3481A certain interface in the iCRM Basic (com_icrmbasic) compon…
- CVE-2009-3482TrustPort Antivirus before 2.8.0.2266 and PC Security before…7.8
- CVE-2009-3483Heap-based buffer overflow in the Create New Site feature in…
- CVE-2009-3484Stack-based buffer overflow in Core FTP 2.1 build 1612 allow…
- CVE-2009-3485Cross-site scripting (XSS) vulnerability in the J-Web interf…
- CVE-2009-3486Multiple cross-site scripting (XSS) vulnerabilities in the J…
- CVE-2009-3488Cross-site scripting (XSS) vulnerability in the Bibliography…
- CVE-2009-3489Adobe Photoshop Elements 8.0 installs the Adobe Active File …7.8
- CVE-2009-3490GNU Wget before 1.12 does not properly handle a '\0' charact…
- CVE-2009-3491SQL injection vulnerability in the Kinfusion SportFusion (co…
- CVE-2009-3492Multiple PHP remote file inclusion vulnerabilities in Loggix…
- CVE-2009-3493Multiple cross-site scripting (XSS) vulnerabilities in Zenas…
Are you affected by CVE-2009-3487?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
