First published: Wed Dec 23 2009(Updated: )
Cross-site scripting (XSS) vulnerability in Forms/login1 in American Power Conversion (APC) Switched Rack PDU AP7932 B2, running rpdu 3.3.3 or 3.7.0 on AOS 3.3.4, and possibly other versions, allows remote attackers to inject arbitrary web script or HTML via the login_username parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
APC AP7932 B2 | =3.3.3 | |
APC AP7932 B2 | =3.7.0 | |
APC AP7932 B2 Firmware | ||
APC OAS | =3.3.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-4406 has a moderate severity rating due to the potential for remote attackers to exploit the cross-site scripting vulnerability.
CVE-2009-4406 affects APC Switched Rack PDU AP7932 B2 running versions 3.3.3 and 3.7.0.
To fix CVE-2009-4406, upgrade the firmware of the APC Switched Rack PDU AP7932 B2 to a version that remediates the vulnerability.
The impact of CVE-2009-4406 allows remote attackers to inject arbitrary web scripts or HTML, potentially compromising user sessions.
CVE-2009-4406 is not specific to any operating system version but is associated with APC AOS version 3.3.4.