Unrated severityNVD Advisory· Published Sep 30, 2009· Updated Apr 23, 2026
CVE-2009-3485
CVE-2009-3485
Description
Cross-site scripting (XSS) vulnerability in the J-Web interface in Juniper JUNOS 8.5R1.14 and 9.0R1.1 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the default URI.
Affected products
2cpe:2.3:o:juniper:junos:8.5:r1.14:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:juniper:junos:8.5:r1.14:*:*:*:*:*:*
- cpe:2.3:o:juniper:junos:9.0:r1.1:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- www.procheckup.com/vulnerability_manager/vulnerabilities/pr09-08nvdExploit
- www.securityfocus.com/bid/36537nvdExploit
- secunia.com/advisories/36829nvdVendor Advisory
- www.vupen.com/english/advisories/2009/2784nvdVendor Advisory
News mentions
0No linked articles in our index yet.