PT-2007-5475 · Cisco · Cisco Unified Meetingplace Web Conferencing

Publicado

2007-08-09

·

Atualizado

2018-10-15

·

CVE-2007-4284

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Cisco Unified MeetingPlace Web Conferencing versions 5.3.235.0 and earlier
Description The issue allows remote attackers to inject arbitrary HTML and web script via the Success Template (STPL) and Failure Template (FTPL) parameters, which are not properly handled in an error message. This can lead to cross-site scripting (XSS) attacks.
Recommendations For versions 5.3.235.0 and earlier, consider disabling the Success Template (STPL) and Failure Template (FTPL) parameters until a patch is available to properly handle these parameters in error messages. Restrict access to error messages that may contain user-supplied input to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-4284

Produtos afetados

Cisco Unified Meetingplace Web Conferencing