CVE Database
/

CVE-2009-0237

Back to search

CVE-2009-0237

Published: Apr 15, 2009

Modified: Aug 7, 2024

PUBLISHED

Description

Cross-site scripting (XSS) vulnerability in cookieauth.dll in the HTML forms authentication component in Microsoft Forefront Threat Management Gateway, Medium Business Edition (TMG MBE); and Internet Security and Acceleration (ISA) Server 2006, 2006 Supportability Update, and 2006 SP1; allows remote attackers to inject arbitrary web script or HTML via "authentication input" to this component, aka "Cross-Site Scripting Vulnerability."

VendorProductVersions

n/a

n/a

affected
n/a

References

MS09-016
vendor-advisory
x_refsource_MS
53637
vdb-entry
x_refsource_OSVDB
TA09-104A
third-party-advisory
x_refsource_CERT
oval:org.mitre.oval:def:5771
vdb-entry
signature
x_refsource_OVAL
ADV-2009-1030
vdb-entry
x_refsource_VUPEN
1022046
vdb-entry
x_refsource_SECTRACK
34687
third-party-advisory
x_refsource_SECUNIA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now