JVN/CVE DB Demo

CVE Reference

Id
444429  
CVE No.
CVE-2009-3018  
Reference
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6524  

Actions

  • List JVN
  • List CVE
  • List NVD
  • CakePHP
  • History
    +

    Request History

    4 previous requests available
    • Restore to current request
    • nvdinfos/index/page:756/sort:reject/direction:asc
    • jvninfos/index/page:1309/sort:last_updated_date/direction:desc/Jvninfos:cveinfos
    • cvereves/view/630789
    • nvdreves/view/430768
    ====
  • Session
    +

    Session

    • 0(null)
    ====
  • Request
    +

    Request

    Cake Params

    • plugin(null)
    • controllercvereves
    • actionview
    • named(empty)
    • pass(array)
      • 0444429

    Post data

    No post data.

    Query string

    No querystring data.

    Cookie

    To view Cookies, add CookieComponent to Controller

    Current Route

    • keys(array)
      • 0controller
      • 1action
    • options(array)
      • defaultRoute(true)
    • defaults(array)
      • plugin(null)
    • template/:controller/:action/*
    ====
  • Sql Log
    +

    Sql Logs

    default

    No query logs.
    ====
  • Timer
    +

    Memory

    Peak Memory Use 3.60 MB

    Message Memory use
    Component initialization 1.38 MB
    Controller action start 1.49 MB
    Controller render start 2.13 MB
    View render complete 2.52 MB

    Timers

    Total Request Time: 15 (ms)

    Message Time in ms Graph
    Core Processing (Derived from $_SERVER["REQUEST_TIME"]) 2.55
    Event: Controller.initialize 0.02
    Event: Controller.startup 0.06
    Controller action 2.44
    Event: Controller.beforeRender 4.00
    » Processing toolbar data 3.95
    Rendering View 2.40
    » Event: View.beforeRender 0.02
    » Rendering APP/View/Cvereves/view.ctp 1.59
    » Event: View.afterRender 0.02
    » Event: View.beforeLayout 0.02
    » Rendering APP/View/Layouts/default.ctp 0.44
    » » Rendering CORE/Cake/View/Elements/sql_dump.ctp 0.07
    Event: View.afterLayout 0.00
    ====
  • Log
    +

    Logs

    There were no log entries made this request

    ====
  • Variables
    +

    View Variables

    • cveref(array)
      • Cveref(array)
        • id444429
        • cveinfo_id40453
        • name(null)
        • cveinfo_nameCVE-2009-3018
        • referenceURL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6524
        • deleted(null)
        • created0000-00-00 00:00:00
        • modified0000-00-00 00:00:00
      • Cveinfo(array)
        • id40453
        • nameCVE-2009-3018
        • statusCandidate
        • descriptionMaxthon Browser 3.0.0.145 Alpha with Ultramode does not properly block javascript: and data: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header that contains a javascript: URI, (2) entering a javascript: URI when specifying the content of a Refresh header, (3) injecting a Refresh header that contains JavaScript sequences in a data:text/html URI, or (4) entering a data:text/html URI with JavaScript sequences when specifying the content of a Refresh header; does not properly block data: URIs in Location headers in HTTP responses, which allows user-assisted remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (5) injecting a Location header that contains JavaScript sequences in a data:text/html URI or (6) entering a data:text/html URI with JavaScript sequences when specifying the content of a Location header; and does not properly handle javascript: URIs in HTML links within (a) 301 and (b) 302 error documents sent from web servers, which allows user-assisted remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (7) injecting a Location HTTP response header or (8) specifying the content of a Location HTTP response header.
        • phaseAssigned (20090831)
        • votesNone (candidate not yet proposed)
        • comments(null)
        • deleted(null)
        • created0000-00-00 00:00:00
        • modified0000-00-00 00:00:00
    • $request->data(empty)
    • $this->validationErrors(array)
      • Cveref(empty)
      • Cveinfo(empty)
    • Loaded Helpers(array)
      • 0Number
      • 1SimpleGraph
      • 2DebugTimer
      • 3Toolbar
      • 4Html
      • 5Text
      • 6Form
      • 7Session
      • 8HtmlToolbar
    ====
  • Environment
    +

    App Constants

    No application environment available.

    CakePHP Constants

    Constant Value
    APP /virtual/inogo77/public_html/jvn/app/
    APP_DIR app
    APPLIBS /virtual/inogo77/public_html/jvn/app/Lib/
    CACHE /virtual/inogo77/public_html/jvn/app/tmp/cache/
    CAKE /virtual/inogo77/public_html/jvn/lib/Cake/
    CAKE_CORE_INCLUDE_PATH /virtual/inogo77/public_html/jvn/lib
    CORE_PATH /virtual/inogo77/public_html/jvn/lib/
    CAKE_VERSION 2.6.0
    CSS /virtual/inogo77/public_html/jvn/app/webroot/css/
    CSS_URL css/
    DS /
    FULL_BASE_URL http://inogo77.s500.xrea.com
    IMAGES /virtual/inogo77/public_html/jvn/app/webroot/img/
    IMAGES_URL img/
    JS /virtual/inogo77/public_html/jvn/app/webroot/js/
    JS_URL js/
    LOGS /virtual/inogo77/public_html/jvn/app/tmp/logs/
    ROOT /virtual/inogo77/public_html/jvn
    TESTS /virtual/inogo77/public_html/jvn/app/Test/
    TMP /virtual/inogo77/public_html/jvn/app/tmp/
    VENDORS /virtual/inogo77/public_html/jvn/vendors/
    WEBROOT_DIR webroot
    WWW_ROOT /virtual/inogo77/public_html/jvn/app/webroot/

    PHP Environment

    Environment Variable Value
    Php Version 5.6.40
    Phprc php56.ini
    Php Fcgi Children 1
    Pwd /virtual/inogo77/public_html/.fast-cgi-bin
    Php Fcgi Max Requests 10000
    Shlvl 0
    Path /usr/local/bin:/usr/bin:/bin
    Http Connection close
    Script Name /jvn/app/webroot/index.php
    Request Uri /jvn/cvereves/view/444429
    Query String
    Request Method GET
    Server Protocol HTTP/1.1
    Gateway Interface CGI/1.1
    Redirect Url /jvn/app/webroot/cvereves/view/444429
    Remote Port 4897
    Script Filename /virtual/inogo77/public_html/jvn/app/webroot/index.php
    Server Admin [no address given]
    Context Document Root /virtual/inogo77/public_html
    Context Prefix
    Request Scheme http
    Document Root /virtual/inogo77/public_html
    Remote Addr 3.14.146.45
    Server Port 80
    Server Addr 160.251.151.205
    Server Name inogo77.s500.xrea.com
    Server Software Apache
    Server Signature
    Http Host inogo77.s500.xrea.com
    Http Accept Encoding gzip, br, zstd, deflate
    Http Cookie advanced-frontend=qa8rea8h1he7ehs239p3lt5fi5
    Http User Agent Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com)
    Http Accept */*
    Gem Home /usr/local/rvm/gems/ruby-2.3.0
    X Dostranslated Ip 3.14.146.45
    Mm Country Code US
    Mmdb Info result found
    Mmdb Addr 3.14.146.45
    Unique Id aCworafp9A1haxyolx9HyQAAAZo
    Redirect Status 200
    Redirect Gem Home /usr/local/rvm/gems/ruby-2.3.0
    Redirect X Dostranslated Ip 3.14.146.45
    Redirect Mm Country Code US
    Redirect Mmdb Info result found
    Redirect Mmdb Addr 3.14.146.45
    Redirect Unique Id aCworafp9A1haxyolx9HyQAAAZo
    Redirect Redirect Status 200
    Redirect Redirect Gem Home /usr/local/rvm/gems/ruby-2.3.0
    Redirect Redirect X Dostranslated Ip 3.14.146.45
    Redirect Redirect Mm Country Code US
    Redirect Redirect Mmdb Info result found
    Redirect Redirect Mmdb Addr 3.14.146.45
    Redirect Redirect Unique Id aCworafp9A1haxyolx9HyQAAAZo
    Fcgi Role RESPONDER
    Php Self /jvn/app/webroot/index.php
    Request Time Float 1747724461.9614
    Request Time 1747724461
    ====
  • Include
    +

    Included Files

    Include Paths

    • 0/virtual/inogo77/public_html/jvn/lib
    • 2/opt/remi/php56/root/usr/share/pear
    • 3/opt/remi/php56/root/usr/share/php
    • 4/usr/share/pear
    • 5/usr/share/php
    • 6-> /virtual/inogo77/public_html/jvn/lib/Cake/

    Included Files

    • core(array)
      • Cache(array)
        • 0CORE/Cache/Cache.php
        • 1CORE/Cache/Engine/FileEngine.php
        • 2CORE/Cache/CacheEngine.php
      • Component(array)
        • 0CORE/Controller/Component/SessionComponent.php
        • 1CORE/Controller/Component/PaginatorComponent.php
      • Config(array)
        • 0CORE/Config/routes.php
        • 1CORE/Config/config.php
      • Controller(array)
        • 0CORE/Controller/Controller.php
        • 1CORE/Controller/ComponentCollection.php
        • 2CORE/Controller/Component.php
      • Datasource(array)
        • 0CORE/Model/Datasource/CakeSession.php
        • 1CORE/Model/Datasource/Database/Mysql.php
        • 2CORE/Model/Datasource/DboSource.php
        • 3CORE/Model/Datasource/DataSource.php
      • Error(array)
        • 0CORE/Error/exceptions.php
        • 1CORE/Error/ErrorHandler.php
      • I18n(array)
        • 0CORE/I18n/I18n.php
        • 1CORE/I18n/L10n.php
      • Log(array)
        • 0CORE/Log/CakeLog.php
        • 1CORE/Log/LogEngineCollection.php
        • 2CORE/Log/Engine/FileLog.php
        • 3CORE/Log/Engine/BaseLog.php
        • 4CORE/Log/CakeLogInterface.php
      • Model(array)
        • 0CORE/Model/Model.php
        • 1CORE/Model/BehaviorCollection.php
        • 2CORE/Model/ConnectionManager.php
      • Network(array)
        • 0CORE/Network/CakeRequest.php
        • 1CORE/Network/CakeResponse.php
      • Other(array)
        • 0CORE/bootstrap.php
        • 1CORE/basics.php
        • 2CORE/Core/App.php
        • 3CORE/Core/Configure.php
        • 4CORE/Core/CakePlugin.php
        • 5CORE/Event/CakeEventListener.php
        • 6CORE/Event/CakeEvent.php
        • 7CORE/Event/CakeEventManager.php
        • 8CORE/Core/Object.php
      • Routing(array)
        • 0CORE/Routing/Dispatcher.php
        • 1CORE/Routing/Filter/AssetDispatcher.php
        • 2CORE/Routing/DispatcherFilter.php
        • 3CORE/Routing/Filter/CacheDispatcher.php
        • 4CORE/Routing/Router.php
        • 5CORE/Routing/Route/CakeRoute.php
        • 6CORE/Routing/Route/PluginShortRoute.php
      • Utility(array)
        • 0CORE/Utility/Hash.php
        • 1CORE/Utility/Inflector.php
        • 2CORE/Utility/ObjectCollection.php
        • 3CORE/Utility/Debugger.php
        • 4CORE/Utility/String.php
        • 5CORE/Utility/ClassRegistry.php
      • View(array)
        • 0CORE/View/HelperCollection.php
    • app(array)
      • Config(array)
        • 0APP/Config/core.php
        • 1APP/Config/bootstrap.php
        • 2APP/Config/routes.php
        • 3APP/Config/database.php
      • Controller(array)
        • 0APP/Controller/CverevesController.php
        • 1APP/Controller/AppController.php
      • Model(array)
        • 0APP/Model/Cveref.php
        • 1APP/Model/AppModel.php
        • 2APP/Model/Cveinfo.php
      • Other(array)
        • 0APP/webroot/index.php
    • plugins(array)
      • DebugKit(array)
        • Component(array)
          • 0DebugKit/Controller/Component/ToolbarComponent.php
        • Other(array)
          • 0DebugKit/Lib/DebugMemory.php
          • 1DebugKit/Lib/Panel/HistoryPanel.php
          • 2DebugKit/Lib/DebugPanel.php
          • 3DebugKit/Lib/Panel/SessionPanel.php
          • 4DebugKit/Lib/Panel/RequestPanel.php
          • 5DebugKit/Lib/Panel/SqlLogPanel.php
          • 6DebugKit/Lib/Panel/TimerPanel.php
          • 7DebugKit/Lib/Panel/LogPanel.php
          • 8DebugKit/Lib/Panel/VariablesPanel.php
          • 9DebugKit/Lib/Panel/EnvironmentPanel.php
          • 10DebugKit/Lib/Panel/IncludePanel.php
          • 11DebugKit/Lib/DebugTimer.php
        • Log(array)
          • 0DebugKit/Lib/Log/Engine/DebugKitLog.php
    ====