Unrated severityNVD Advisory· Published Jul 13, 2009· Updated Apr 23, 2026
CVE-2009-2437
CVE-2009-2437
Description
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Rentventory 1.0.1 allow remote attackers to inject arbitrary web script or HTML via the (1) username (aka Login) and (2) password parameters in a login action.
Affected products
1- cpe:2.3:a:rentventory:rentventory:1.0.1:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- packetstormsecurity.org/0907-exploits/rentventory-xss.txtnvdExploit
- secunia.com/advisories/35749nvdVendor Advisory
- www.vupen.com/english/advisories/2009/1835nvdVendor Advisory
News mentions
0No linked articles in our index yet.