Lucene search

K
nvd[email protected]NVD:CVE-2008-4542
HistoryOct 13, 2008 - 8:00 p.m.

CVE-2008-4542

2008-10-1320:00:02
CWE-79
web.nvd.nist.gov
8

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

AI Score

5.3

Confidence

High

EPSS

0.001

Percentile

45.5%

Cross-site scripting (XSS) vulnerability in Cisco Unity 4.x before 4.2(1)ES162, 5.x before 5.0(1)ES56, and 7.x before 7.0(2)ES8 allows remote authenticated administrators to inject arbitrary web script or HTML by entering it in the database (aka data store).

Affected configurations

Nvd
Node
ciscounityRange4.2\(1\)
OR
ciscounityRange5.0\(1\)
OR
ciscounityRange7.0\(2\)
OR
ciscounityMatch4.0
OR
ciscounityMatch4.0\(1\)
OR
ciscounityMatch4.0\(2\)
OR
ciscounityMatch4.0\(3\)
OR
ciscounityMatch4.0\(3\)sr2
OR
ciscounityMatch4.0\(4\)
OR
ciscounityMatch4.0\(4\)sr1
OR
ciscounityMatch4.0\(5\)
OR
ciscounityMatch4.1\(1\)
OR
ciscounityMatch5.0
OR
ciscounityMatch7.0
VendorProductVersionCPE
ciscounity*cpe:2.3:a:cisco:unity:*:*:*:*:*:*:*:*
ciscounity4.0cpe:2.3:a:cisco:unity:4.0:*:*:*:*:*:*:*
ciscounity4.0(1)cpe:2.3:a:cisco:unity:4.0\(1\):*:*:*:*:*:*:*
ciscounity4.0(2)cpe:2.3:a:cisco:unity:4.0\(2\):*:*:*:*:*:*:*
ciscounity4.0(3)cpe:2.3:a:cisco:unity:4.0\(3\):*:*:*:*:*:*:*
ciscounity4.0(3)cpe:2.3:a:cisco:unity:4.0\(3\):sr2:*:*:*:*:*:*
ciscounity4.0(4)cpe:2.3:a:cisco:unity:4.0\(4\):*:*:*:*:*:*:*
ciscounity4.0(4)cpe:2.3:a:cisco:unity:4.0\(4\):sr1:*:*:*:*:*:*
ciscounity4.0(5)cpe:2.3:a:cisco:unity:4.0\(5\):*:*:*:*:*:*:*
ciscounity4.1(1)cpe:2.3:a:cisco:unity:4.1\(1\):*:*:*:*:*:*:*
Rows per page:
1-10 of 121

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

AI Score

5.3

Confidence

High

EPSS

0.001

Percentile

45.5%

Related for NVD:CVE-2008-4542