5

CVE-2009-1432

Symantec Reporting Server, as used in Symantec AntiVirus (SAV) Corporate Edition 10.1 before 10.1 MR8 and 10.2 before 10.2 MR2, Symantec Client Security (SCS) before 3.1 MR8, and the Symantec Endpoint Protection Manager (SEPM) component in Symantec Endpoint Protection (SEP) before 11.0 MR2, allows remote attackers to inject arbitrary text into the login screen, and possibly conduct phishing attacks, via vectors involving a URL that is not properly handled.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SymantecAntivirus Version10.1 Update- SwEditioncorporate
SymantecAntivirus Version10.1 Updatemaintenance_release7 SwEditioncorporate
SymantecAntivirus Version10.2 Update- SwEditioncorporate
SymantecAntivirus Version10.2 Updatemaintenance_release1 SwEditioncorporate
SymantecClient Security Version3.1 Update-
SymantecClient Security Version3.1 Updatemaintenance_release7
SymantecEndpoint Protection Version11.0 Update-
SymantecEndpoint Protection Version11.0 Updatemaintenance_release1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.18% 0.828
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.