CVE-2009-1798 EXPLOIT
4.3
MEDIUM · CVSS 2.0 · EPSS 2% (pctl 80)
Patch early
A public exploit exists.
Description
Multiple cross-site scripting (XSS) vulnerabilities on the Network Management Card (NMC) on American Power Conversion (APC) Switched Rack PDU (aka Rack Mount Power Distribution) devices and other devices allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: the login_username vector for Forms/login1 is already covered by CVE-2009-4406.
Scoring
| CVSS | 4.3 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
| EPSS | 1.99% — more likely to be exploited than 80% of all CVEs |
| Weakness | CWE-79 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2009-12-28 |
| Last modified | 2026-06-16 |
Affected (2)
| Vendor | Product |
|---|---|
| apc | network management card |
| apc | switched rack pdu |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | APC Network Management Card - Cross-Site Request Forgery / Cross-Site Scripting | 2009-12-15 |
References
- http://holisticinfosec.org/content/view/111/45/
- http://nam-en.apc.com/cgi-bin/nam_en.cfg/php/enduser/std_adp.php?p_faqid=10887
- http://secunia.com/advisories/37744
- http://www.kb.cert.org/vuls/id/166739
- http://holisticinfosec.org/content/view/111/45/
- http://nam-en.apc.com/cgi-bin/nam_en.cfg/php/enduser/std_adp.php?p_faqid=10887
- http://secunia.com/advisories/37744
- http://www.kb.cert.org/vuls/id/166739
→ the Explorer · watch your stack · NVD