CVE-2009-1593 Information
Feb 14, 2021
cve
Description
Armorlogic Profense Web Application Firewall before 2.2.22 and 2.4.x before 2.4.4 does not properly implement the \negative model\ which allows remote attackers to conduct cross-site scripting (XSS) attacks via a modified end tag of a SCRIPT element.
Reference
http://resources.enablesecurity.com/advisories/ES-20090500-profense.txt http://www.securityfocus.com/archive/1/503649/100/0/threaded http://www.securityfocus.com/bid/35053 http://www.webappsec.org/lists/websecurity/archive/2009-05/msg00040.html https://exchange.xforce.ibmcloud.com/vulnerabilities/50663
Share on: