{"api_version":"1","generated_at":"2026-07-23T13:19:03+00:00","cve":"CVE-2009-0860","urls":{"html":"https://cve.report/CVE-2009-0860","api":"https://cve.report/api/cve/CVE-2009-0860.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2009-0860","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2009-0860"},"summary":{"title":"CVE-2009-0860","description":"Cross-site scripting (XSS) vulnerability in the web user interface in the login application in NetMRI 3.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to error pages.","state":"PUBLISHED","assigner":"mitre","published_at":"2009-03-10 14:30:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-79","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.securityfocus.com/archive/1/501033/100/0/threaded","name":"http://www.securityfocus.com/archive/1/501033/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/33963","name":"http://secunia.com/advisories/33963","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"NetMRI Unspecified Cross-Site Scripting Vulnerability - Secunia Advisories - Vulnerability Information - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/33824","name":"http://www.securityfocus.com/bid/33824","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"NetMRI Login Application Error Page Cross Site Scripting Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://connection.netcordia.com/forums/t/731.aspx","name":"http://connection.netcordia.com/forums/t/731.aspx","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Cross Site Scripting Vulnerability in NetMRI - Patch available - Netcordia Connection","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2009-0860","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2009-0860","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2009","cve_id":"860","vulnerable":"1","versionEndIncluding":"3.0.1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"netcordia","cpe5":"netmri","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T04:48:52.657Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"33824","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/33824"},{"name":"33963","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/33963"},{"name":"20090218 DDIVRT-2009-20 NetMRI Login Application Cross-site Scripting Vulnerability","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/501033/100/0/threaded"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://connection.netcordia.com/forums/t/731.aspx"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2009-01-19T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in the web user interface in the login application in NetMRI 3.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to error pages."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-10T18:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"33824","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/33824"},{"name":"33963","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/33963"},{"name":"20090218 DDIVRT-2009-20 NetMRI Login Application Cross-site Scripting Vulnerability","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/501033/100/0/threaded"},{"tags":["x_refsource_CONFIRM"],"url":"http://connection.netcordia.com/forums/t/731.aspx"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2009-0860","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site scripting (XSS) vulnerability in the web user interface in the login application in NetMRI 3.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to error pages."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"33824","refsource":"BID","url":"http://www.securityfocus.com/bid/33824"},{"name":"33963","refsource":"SECUNIA","url":"http://secunia.com/advisories/33963"},{"name":"20090218 DDIVRT-2009-20 NetMRI Login Application Cross-site Scripting Vulnerability","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/501033/100/0/threaded"},{"name":"http://connection.netcordia.com/forums/t/731.aspx","refsource":"CONFIRM","url":"http://connection.netcordia.com/forums/t/731.aspx"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2009-0860","datePublished":"2009-03-10T14:00:00.000Z","dateReserved":"2009-03-10T00:00:00.000Z","dateUpdated":"2024-08-07T04:48:52.657Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2009-03-10 14:30:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-79","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:netcordia:netmri:*:*:*:*:*:*:*:*","versionEndIncluding":"3.0.1","matchCriteriaId":"E7EA052B-9EBE-48FC-A860-768E2F17B0F2"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2009","CveId":"860","Ordinal":"1","Title":"CVE-2009-0860","CVE":"CVE-2009-0860","Year":"2009"},"notes":[{"CveYear":"2009","CveId":"860","Ordinal":"1","NoteData":"Cross-site scripting (XSS) vulnerability in the web user interface in the login application in NetMRI 3.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to error pages.","Type":"Description","Title":"CVE-2009-0860"},{"CveYear":"2009","CveId":"860","Ordinal":"2","NoteData":"2009-03-10","Type":"Other","Title":"Published"},{"CveYear":"2009","CveId":"860","Ordinal":"3","NoteData":"2018-10-10","Type":"Other","Title":"Modified"}]}}}