Vulnslist

find the latest Cisco vulnerabilities

Cisco Unified MeetingPlace Template Cross-Site Scripting Vulnerability

Cisco-SA-20070808-CVE-2007-4284 · Medium · Published · Updated

Cisco Unified MeetingPlace versions prior to 5.3.235.0 contain a vulnerability that could allow an unauthenticated, remote attacker to conduct cross-site scripting attacks. This vulnerability exists due to insufficient filtering of parameters by Cisco Unified MeetingPlace.  An unauthenticated, remote attacker could exploit this vulnerability by convincing a user to follow a malicious link.  When followed, the link could trigger the execution of arbitrary script code or HTML within a user's browser session in the security context of the Cisco Unified MeetingPlace site. Cisco confirmed this vulnerability in a security response and released updated software. To exploit this vulnerability, an attacker must convince a user to follow a malicious URL, likely provided within an e-mail message.  Prior to an exploit, the user must have a valid, logged-in session to the affected application or log in as part of an exploit attempt.  As a result of successful exploitation, the attacker could execute arbitrary script code in the user's browser session within the Cisco Unified MeetingPlace application.  An exploit could allow the attacker to gain access to sensitive browser-based information or possibly take actions on the affected site as the user. Software versions 5.3.333.0 and later have been corrected to return a properly formatted XML message.

Workarounds

Administrators are advised to apply the available software updates.

Users are advised not to visit untrusted websites.

Users are advised not to open e-mail from untrusted sources.

Users are advised not to follow unsolicited links.  Users should verify the authenticity of an unexpected link from a trusted source prior to following it.

For additional information on cross-site scripting attacks and methods, users are advised to reference the Cisco Applied Mitigation Bulletin Understanding Cross-Site Scripting Threat Vectorshttp://www.cisco.com/warp/public/707/cisco-air-20060922-understanding-xss.shtml .

CVEsCVE-2007-4284
Cisco Bug IDsNA
CVSS ScoreBase 1.9
Product Names From Source
Cisco Unified MeetingPlace

CSAF Product Statuses

Product Status Source CVE Rows
Cisco Unified MeetingPlace known_affected cisco_csaf CVE-2007-4284 1

Related Products

Product CVE Evidence
Cisco Unified MeetingPlace CVE-2007-4284 Cisco OpenVuln