CVE-2009-0307
Summary
| CVE | CVE-2009-0307 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-04-22 18:30:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Cross-site scripting (XSS) vulnerability in the "Customize Statistics Page" (admin/statistics/ConfigureStatistics) in the MDS Connection Service in Research in Motion (RIM) BlackBerry Enterprise Server (BES) before 4.1.6 MR5 allows remote attackers to inject arbitrary web script or HTML via the (1) customDate, (2) interval, (3) lastCustomInterval, (4) lastIntervalLength, (5) nextCustomInterval, (6) nextIntervalLength, (7) action, (8) delIntervalIndex, (9) addStatIndex, (10) delStatIndex, and (11) referenceTime parameters. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Rim | Blackberry Enterprise Server | 4.0 | All | All | All |
| Application | Rim | Blackberry Enterprise Server | 4.0 | sp3 | All | All |
| Application | Rim | Blackberry Enterprise Server | 4.0.3 | All | All | All |
| Application | Rim | Blackberry Enterprise Server | 4.1 | All | All | All |
| Application | Rim | Blackberry Enterprise Server | 4.1 | sp3 | All | All |
| Application | Rim | Blackberry Enterprise Server | 4.1.3 | All | All | All |
| Application | Rim | Blackberry Enterprise Server | 4.1.4 | All | All | All |
| Application | Rim | Blackberry Enterprise Server | 4.1.5 | All | All | All |
| Application | Rim | Blackberry Enterprise Server | 4.1.6 | All | All | All |
| Application | Rim | Blackberry Enterprise Server | All | mr4 | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.blackberry.com/btsc/dynamickc.do | af854a3a-2127-422b-91ae-364da2661108 | www.blackberry.com | Vendor Advisory |
| BlackBerry Enterprise Server MDS Connection Service Cross Site Scripting Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Exploit |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| BlackBerry Enterprise Server Input Validation Flaw in MDS Connection Service Permits Cross-Site Scripting Attacks - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| NEOHAPSIS - Peace of Mind Through Integrity and Insight | af854a3a-2127-422b-91ae-364da2661108 | archives.neohapsis.com | |
| BlackBerry Enterprise Server MDS Connection Service Cross-Site Scripting - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| osvdb.org/53772 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.