{"id":"CVE-2009-3015","details":"QtWeb 3.0 Builds 001 and 003 does not properly block javascript: and data: URIs in Refresh and Location headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header that contains a javascript: URI, (2) entering a javascript: URI when specifying the content of a Refresh header, (3) injecting a Refresh header that contains JavaScript sequences in a data:text/html URI, (4) entering a data:text/html URI with JavaScript sequences when specifying the content of a Refresh header, (5) injecting a Location header that contains JavaScript sequences in a data:text/html URI, or (6) entering a data:text/html URI with JavaScript sequences when specifying the content of a Location header.","modified":"2024-06-04T04:53:58.998826Z","published":"2009-08-31T16:30:06Z","withdrawn":"2024-06-30T15:58:28.747392Z","references":[{"type":"EVIDENCE","url":"http://websecurity.com.ua/3386/"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/52993"}],"affected":[{"package":{"name":"kde4libs","ecosystem":"Debian:10","purl":"pkg:deb/debian/kde4libs?arch=source"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["4:4.14.38-3","4:4.14.38-4","4:4.14.38-4~exp1"],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2009-3015.json"}},{"package":{"name":"qt4-x11","ecosystem":"Debian:10","purl":"pkg:deb/debian/qt4-x11?arch=source"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["4:4.8.7+dfsg-18","4:4.8.7+dfsg-18+deb10u1","4:4.8.7+dfsg-18+deb10u2","4:4.8.7+dfsg-19","4:4.8.7+dfsg-20"],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2009-3015.json"}}],"schema_version":"1.7.3"}