CVE-2009-0237: XSS
Cross-site scripting (XSS) vulnerability in cookieauth.dll in the HTML forms authentication component in Microsoft Forefront Threat Management Gateway, Medium Business Edition (TMG MBE); and Internet Security and Acceleration (ISA) Server 2006, 2006 Supportability Update, and 2006 SP1; allows remote attackers to inject arbitrary web script or HTML via "authentication input" to this component, aka "Cross-Site Scripting Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0237?
CVE-2009-0237 is classified as a medium severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2009-0237?
To fix CVE-2009-0237, ensure you are running the latest patches and updates provided by Microsoft for affected versions.
Which software is affected by CVE-2009-0237?
CVE-2009-0237 affects Microsoft Internet Security and Acceleration Server 2004 SP3, 2006, and Microsoft Forefront Threat Management Gateway.
What type of vulnerability is CVE-2009-0237?
CVE-2009-0237 is a cross-site scripting (XSS) vulnerability found in cookieauth.dll.
Can CVE-2009-0237 be exploited remotely?
Yes, CVE-2009-0237 can be exploited remotely by attackers leveraging the XSS vulnerability.