PT-2007-5475 · Cisco · Cisco Unified Meetingplace Web Conferencing

Published

2007-08-09

·

Updated

2018-10-15

·

CVE-2007-4284

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Cisco Unified MeetingPlace Web Conferencing versions 5.3.235.0 and earlier
Description The issue allows remote attackers to inject arbitrary HTML and web script via the Success Template (STPL) and Failure Template (FTPL) parameters, which are not properly handled in an error message. This can lead to cross-site scripting (XSS) attacks.
Recommendations For versions 5.3.235.0 and earlier, consider disabling the Success Template (STPL) and Failure Template (FTPL) parameters until a patch is available to properly handle these parameters in error messages. Restrict access to error messages that may contain user-supplied input to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-4284

Affected Products

Cisco Unified Meetingplace Web Conferencing