CWE
79
Advisory Published
Updated

CVE-2009-3731: XSS

First published: Wed Dec 16 2009(Updated: )

Multiple cross-site scripting (XSS) vulnerabilities in WebWorks Help 2.0 through 5.0 in VMware vCenter 4.0 before Update 1 Build 208156; VMware Server 2.0.2; VMware ESX 4.0; VMware Lab Manager 2.x; VMware vCenter Lab Manager 3.x and 4.x before 4.0.1; VMware Stage Manager 1.x before 4.0.1; WebWorks Publisher 6.x through 8.x; WebWorks Publisher 2003; and WebWorks ePublisher 9.0.x through 9.3, 2008.1 through 2008.4, and 2009.x before 2009.3 allow remote attackers to inject arbitrary web script or HTML via (1) wwhelp_entry.html, reachable through index.html and wwhsec.htm, (2) wwhelp/wwhimpl/api.htm, (3) wwhelp/wwhimpl/common/html/frameset.htm, (4) wwhelp/wwhimpl/common/scripts/switch.js, or (5) the window.opener component in wwhelp/wwhimpl/common/html/bookmark.htm, related to (a) unspecified parameters and (b) messages used in topic links for the bookmarking functionality.

Credit: cve@mitre.org

Affected SoftwareAffected VersionHow to fix
WebWorks Publisher=9.0
WebWorks Publisher=9.1
WebWorks Publisher=9.2
WebWorks Publisher=9.3
WebWorks Publisher=2008.1
WebWorks Publisher=2008.2
WebWorks Publisher=2008.3
WebWorks Publisher=2008.4
WebWorks Publisher=2009.1
WebWorks Publisher=2009.2
WebWorks Help=2.0
WebWorks Help=3.0
WebWorks Help=4.0
WebWorks Help=5.0
WebWorks ePublisher=6.0
WebWorks ePublisher=7.0
WebWorks ePublisher=8.0
WebWorks ePublisher=2003
VMware vCenter=4.0
Microsoft Windows
VMware ESXi=4.0
Jenkins VMware Lab Manager Slaves=2.0
VMware Server=2.0.2
Stage Manager Education<=4.0
Stage Manager Education=1.0
VMware Lab Manager=3.0
VMware Lab Manager=3.0.1
VMware Lab Manager=3.0.2
VMware Lab Manager=4.0
VMware Stage Manager=1.0.1

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of CVE-2009-3731?

    CVE-2009-3731 has a medium severity rating, making it significant but not critical.

  • How do I fix CVE-2009-3731?

    To fix CVE-2009-3731, update affected VMware products to the latest versions as specified in the security advisory.

  • Which VMware products are affected by CVE-2009-3731?

    CVE-2009-3731 affects multiple versions of VMware vCenter, VMware Server, VMware ESX, and WebWorks Help among others.

  • What types of vulnerabilities does CVE-2009-3731 include?

    CVE-2009-3731 includes multiple cross-site scripting (XSS) vulnerabilities.

  • Can I mitigate CVE-2009-3731 without patching?

    While patching is the best solution, implementing proper web application firewalls and input validation can help mitigate CVE-2009-3731.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203