Unrated severityNVD Advisory· Published Mar 16, 2009· Updated Apr 23, 2026
CVE-2009-0917
CVE-2009-0917
Description
Cross-site scripting (XSS) vulnerability in DFLabs PTK 1.0.0 through 1.0.4 allows remote attackers to inject arbitrary web script or HTML by providing a forensic image containing HTML documents, which are rendered in web browsers during inspection by PTK. NOTE: the vendor states that the product is intended for use in a laboratory with "no contact from / to internet."
Affected products
5Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- ptk.dflabs.com/faq.htmlnvdPatchVendor Advisory
- ptk.dflabs.com/security.htmlnvdPatchVendor Advisory
- www.kb.cert.org/vuls/id/845747nvdUS Government Resource
- www.kb.cert.org/vuls/id/RGII-7Q4GBJnvdUS Government Resource
- secunia.com/advisories/34257nvd
- www.securityfocus.com/bid/34111nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/49236nvd
News mentions
0No linked articles in our index yet.