CVE-2009-3015

Source
https://cve.org/CVERecord?id=CVE-2009-3015
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2009-3015.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2009-3015
Withdrawn
2024-06-30T15:58:28.747392Z
Published
2009-08-31T16:30:06Z
Modified
2024-06-04T04:53:58.998826Z
Summary
[none]
Details

QtWeb 3.0 Builds 001 and 003 does not properly block javascript: and data: URIs in Refresh and Location headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header that contains a javascript: URI, (2) entering a javascript: URI when specifying the content of a Refresh header, (3) injecting a Refresh header that contains JavaScript sequences in a data:text/html URI, (4) entering a data:text/html URI with JavaScript sequences when specifying the content of a Refresh header, (5) injecting a Location header that contains JavaScript sequences in a data:text/html URI, or (6) entering a data:text/html URI with JavaScript sequences when specifying the content of a Location header.

References

Affected packages

Debian:10 / kde4libs

Package

Name
kde4libs
Purl
pkg:deb/debian/kde4libs?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

4:4.*
4:4.14.38-3
4:4.14.38-4~exp1
4:4.14.38-4

Ecosystem specific

{
    "urgency": "unimportant"
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2009-3015.json"

Debian:10 / qt4-x11

Package

Name
qt4-x11
Purl
pkg:deb/debian/qt4-x11?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

4:4.*
4:4.8.7+dfsg-18
4:4.8.7+dfsg-18+deb10u1
4:4.8.7+dfsg-18+deb10u2
4:4.8.7+dfsg-19
4:4.8.7+dfsg-20

Ecosystem specific

{
    "urgency": "unimportant"
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2009-3015.json"