Unrated severityNVD Advisory· Published Apr 16, 2009· Updated Apr 23, 2026
CVE-2009-1294
CVE-2009-1294
Description
Multiple cross-site scripting (XSS) vulnerabilities in web/guest/home in the Liferay 4.3.0 portal in Novell Teaming 1.0 through SP3 (1.0.3) allow remote attackers to inject arbitrary web script or HTML via the (1) p_p_state or (2) p_p_mode parameters.
Affected products
5- cpe:2.3:a:liferay:liferay_enterprise_portal:4.3.0:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- www.novell.com/support/php/search.donvdPatchVendor Advisory
- www.securityfocus.com/bid/34531nvdExploit
- www.sec-consult.com/files/20090415-0-novell-teaming.txtnvdExploit
- secunia.com/advisories/34714nvd
- www.securityfocus.com/archive/1/502704/100/0/threadednvd
- www.securitytracker.com/idnvd
- www.vupen.com/english/advisories/2009/1048nvd
News mentions
0No linked articles in our index yet.