Lucene search

K
cveCiscoCVE-2009-2048
HistoryJul 16, 2009 - 3:30 p.m.

CVE-2009-2048

2009-07-1615:30:00
CWE-79
cisco
web.nvd.nist.gov
33
cisco
crs
xss
vulnerability
administration interface
ccx
contact center express
nvd

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

AI Score

5.3

Confidence

High

EPSS

0.001

Percentile

44.5%

Cross-site scripting (XSS) vulnerability in the Administration interface in Cisco Customer Response Solutions (CRS) before 7.0(1) SR2 in Cisco Unified Contact Center Express (aka CCX) server allows remote authenticated users to inject arbitrary web script or HTML into the CCX database via unspecified vectors.

Affected configurations

Nvd
Node
ciscocrsMatch3.5
OR
ciscocrsMatch4.0
OR
ciscocrsMatch4.1
OR
ciscocrsMatch4.5
OR
ciscocrsMatch5.0
OR
ciscocrsMatch6.0
OR
ciscocrsMatch7.0
OR
ciscocustomer_response_applicationsMatch3.5
OR
ciscoip_qmMatch3.5
OR
ciscounified_ccxMatch3.5
OR
ciscounified_ccxMatch4.0\(1\)
OR
ciscounified_ccxMatch4.0\(3\)
OR
ciscounified_ccxMatch4.0\(4\)
OR
ciscounified_ccxMatch4.0\(5\)
OR
ciscounified_ccxMatch4.0\(5a\)
OR
ciscounified_ccxMatch4.5\(1\)
OR
ciscounified_ccxMatch4.5\(2\)
OR
ciscounified_ccxMatch5.0\(1\)
OR
ciscounified_ccxMatch6.0\(1\)
OR
ciscounified_ccxMatch7.0\(1\)
OR
ciscounified_ip_contact_center_expressMatch3.0
OR
ciscounified_ip_contact_center_expressMatch5.0\(1\)
OR
ciscounified_ip_contact_center_expressMatch6.0\(1\)
OR
ciscounified_ip_contact_center_expressMatch7.0
OR
ciscounified_ip_ivrMatch3.0
OR
ciscounified_ip_ivrMatch3.1
OR
ciscounified_ip_ivrMatch4.0
OR
ciscounified_ip_ivrMatch4.1
OR
ciscounified_ip_ivrMatch4.5
OR
ciscounified_ip_ivrMatch5.0
OR
ciscounified_ip_ivrMatch6.0
OR
ciscounified_ip_ivrMatch7.0
OR
ciscounified_ip_ivrMatch7.0\(1\)
VendorProductVersionCPE
ciscocrs3.5cpe:2.3:a:cisco:crs:3.5:*:*:*:*:*:*:*
ciscocrs4.0cpe:2.3:a:cisco:crs:4.0:*:*:*:*:*:*:*
ciscocrs4.1cpe:2.3:a:cisco:crs:4.1:*:*:*:*:*:*:*
ciscocrs4.5cpe:2.3:a:cisco:crs:4.5:*:*:*:*:*:*:*
ciscocrs5.0cpe:2.3:a:cisco:crs:5.0:*:*:*:*:*:*:*
ciscocrs6.0cpe:2.3:a:cisco:crs:6.0:*:*:*:*:*:*:*
ciscocrs7.0cpe:2.3:a:cisco:crs:7.0:*:*:*:*:*:*:*
ciscocustomer_response_applications3.5cpe:2.3:a:cisco:customer_response_applications:3.5:*:*:*:*:*:*:*
ciscoip_qm3.5cpe:2.3:a:cisco:ip_qm:3.5:*:*:*:*:*:*:*
ciscounified_ccx3.5cpe:2.3:a:cisco:unified_ccx:3.5:*:*:*:*:*:*:*
Rows per page:
1-10 of 331

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

AI Score

5.3

Confidence

High

EPSS

0.001

Percentile

44.5%