Lucene search

K
cveMitreCVE-2007-4284
HistoryAug 09, 2007 - 9:17 p.m.

CVE-2007-4284

2007-08-0921:17:00
mitre
web.nvd.nist.gov
19
cve-2007-4284
xss
cisco unified meetingplace
web conferencing
mp 5.3.235.0
nvd
security vulnerability

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.9

Confidence

High

EPSS

0.063

Percentile

93.7%

Multiple cross-site scripting (XSS) vulnerabilities in Cisco Unified MeetingPlace Web Conferencing (MP) 5.3.235.0 and earlier allow remote attackers to inject arbitrary HTML and web script via the (1) Success Template (STPL) and (2) Failure Template (FTPL) parameters, which are not properly handled in an error message.

Affected configurations

Nvd
Node
ciscomeetingplace_web_confrencingRange5.3\(235\)
VendorProductVersionCPE
ciscomeetingplace_web_confrencing*cpe:2.3:a:cisco:meetingplace_web_confrencing:*:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.9

Confidence

High

EPSS

0.063

Percentile

93.7%

Related for CVE-2007-4284