CVE-2009-2907 EXPLOIT
4.3
MEDIUM · CVSS 2.0 · EPSS 1.2% (pctl 67)
Patch early
A public exploit exists.
Description
Multiple cross-site scripting (XSS) vulnerabilities in SpringSource tc Server 6.0.20.B and earlier, Application Management Suite (AMS) before 2.0.0.SR4, Hyperic HQ Open Source before 4.2.x, Hyperic HQ 4.0 Enterprise before 4.0.3.2, and Hyperic HQ 4.1 Enterprise before 4.1.2.1 allow remote attackers to inject arbitrary web script or HTML via the description field and unspecified "input fields."
Scoring
| CVSS | 4.3 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
| EPSS | 1.19% — more likely to be exploited than 67% of all CVEs |
| Weakness | CWE-79 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2010-03-24 |
| Last modified | 2026-06-16 |
Affected (3)
| Vendor | Product |
|---|---|
| springsource | application management suite |
| springsource | hyperic hq |
| springsource | tc server |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | SpringSource (Multiple Products) - Multiple HTML Injection Vulnerabilities | 2010-03-23 |
References
→ the Explorer · watch your stack · NVD