{"api_version":"1","generated_at":"2026-07-23T07:36:14+00:00","cve":"CVE-2009-4352","urls":{"html":"https://cve.report/CVE-2009-4352","api":"https://cve.report/api/cve/CVE-2009-4352.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2009-4352","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2009-4352"},"summary":{"title":"CVE-2009-4352","description":"Multiple cross-site scripting (XSS) vulnerabilities in TransWARE Active! mail 2003 build 2003.0139.0871 and earlier, and possibly other versions before 2003.0139.0939, allow remote attackers to inject arbitrary web script or HTML via the (1) From, (2) To, (3) Cc, and (4) Bcc parameters.","state":"PUBLISHED","assigner":"mitre","published_at":"2009-12-17 18:30:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-79","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://secunia.com/advisories/37602","name":"http://secunia.com/advisories/37602","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Active! Mail 2003 Multiple Vulnerabilities - Secunia Advisories - Vulnerability Information - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/54750","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/54750","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://jvndb.jvn.jp/en/contents/2009/JVNDB-2009-000075.html","name":"http://jvndb.jvn.jp/en/contents/2009/JVNDB-2009-000075.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"JVNDB-2009-000075 - JVN iPedia","mime":"text/xml","httpstatus":"200","archivestatus":"200"},{"url":"http://jvn.jp/en/jp/JVN49083120/index.html","name":"http://jvn.jp/en/jp/JVN49083120/index.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"JVN#49083120 Active! mail 2003 cross-site scripting vulnerability","mime":"text/xml","httpstatus":"200","archivestatus":"200"},{"url":"http://www.transware.co.jp/support_am/security/vulnerability2.html","name":"http://www.transware.co.jp/support_am/security/vulnerability2.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"有償サポートを契約のお客様サポート｜株式会社クオリティア","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2009-4352","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2009-4352","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2009","cve_id":"4352","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"transware","cpe5":"active_mail_2003","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T07:01:20.218Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"37602","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/37602"},{"name":"JVN#49083120","tags":["third-party-advisory","x_refsource_JVN","x_transferred"],"url":"http://jvn.jp/en/jp/JVN49083120/index.html"},{"name":"activemail2003-unspecified-xss(54750)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/54750"},{"name":"JVNDB-2009-000075","tags":["third-party-advisory","x_refsource_JVNDB","x_transferred"],"url":"http://jvndb.jvn.jp/en/contents/2009/JVNDB-2009-000075.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.transware.co.jp/support_am/security/vulnerability2.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2009-12-07T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple cross-site scripting (XSS) vulnerabilities in TransWARE Active! mail 2003 build 2003.0139.0871 and earlier, and possibly other versions before 2003.0139.0939, allow remote attackers to inject arbitrary web script or HTML via the (1) From, (2) To, (3) Cc, and (4) Bcc parameters."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-16T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"37602","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/37602"},{"name":"JVN#49083120","tags":["third-party-advisory","x_refsource_JVN"],"url":"http://jvn.jp/en/jp/JVN49083120/index.html"},{"name":"activemail2003-unspecified-xss(54750)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/54750"},{"name":"JVNDB-2009-000075","tags":["third-party-advisory","x_refsource_JVNDB"],"url":"http://jvndb.jvn.jp/en/contents/2009/JVNDB-2009-000075.html"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.transware.co.jp/support_am/security/vulnerability2.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2009-4352","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple cross-site scripting (XSS) vulnerabilities in TransWARE Active! mail 2003 build 2003.0139.0871 and earlier, and possibly other versions before 2003.0139.0939, allow remote attackers to inject arbitrary web script or HTML via the (1) From, (2) To, (3) Cc, and (4) Bcc parameters."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"37602","refsource":"SECUNIA","url":"http://secunia.com/advisories/37602"},{"name":"JVN#49083120","refsource":"JVN","url":"http://jvn.jp/en/jp/JVN49083120/index.html"},{"name":"activemail2003-unspecified-xss(54750)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/54750"},{"name":"JVNDB-2009-000075","refsource":"JVNDB","url":"http://jvndb.jvn.jp/en/contents/2009/JVNDB-2009-000075.html"},{"name":"http://www.transware.co.jp/support_am/security/vulnerability2.html","refsource":"CONFIRM","url":"http://www.transware.co.jp/support_am/security/vulnerability2.html"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2009-4352","datePublished":"2009-12-17T18:00:00.000Z","dateReserved":"2009-12-17T00:00:00.000Z","dateUpdated":"2024-08-07T07:01:20.218Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2009-12-17 18:30:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-79","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:transware:active_mail_2003:*:*:*:*:*:*:*:*","matchCriteriaId":"1320CAA1-E89A-4599-91E9-388D8F9BCF42"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2009","CveId":"4352","Ordinal":"1","Title":"CVE-2009-4352","CVE":"CVE-2009-4352","Year":"2009"},"notes":[{"CveYear":"2009","CveId":"4352","Ordinal":"1","NoteData":"Multiple cross-site scripting (XSS) vulnerabilities in TransWARE Active! mail 2003 build 2003.0139.0871 and earlier, and possibly other versions before 2003.0139.0939, allow remote attackers to inject arbitrary web script or HTML via the (1) From, (2) To, (3) Cc, and (4) Bcc parameters.","Type":"Description","Title":"CVE-2009-4352"},{"CveYear":"2009","CveId":"4352","Ordinal":"2","NoteData":"2009-12-17","Type":"Other","Title":"Published"},{"CveYear":"2009","CveId":"4352","Ordinal":"3","NoteData":"2017-08-16","Type":"Other","Title":"Modified"}]}}}