← back
CVE-2009-3440

CVE-2009-3440

23Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendepss 1.5%
from disclosure to weapon0 days
Published on NVDSep 28
1st PoCSep 23
exploitation probability
1.5%top 29% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Cross-site scripting (XSS) vulnerability in Open Source Security Information Management (OSSIM) before 2.1.2 allows remote attackers to inject arbitrary web script or HTML via the option parameter to the default URI (aka the main menu).
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.