CVE-2007-4284
Multiple cross-site scripting (XSS) vulnerabilities in Cisco Unified MeetingPlace Web Conferencing (MP) 5.3.235.0 and earlier allow remote attackers to inject arbitrary HTML and web script via the (1) Success Template (STPL) and (2) Failure Template…
Does this matter?
Lower severity and a low EPSS score (1.57%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple cross-site scripting (XSS) vulnerabilities in Cisco Unified MeetingPlace Web Conferencing (MP) 5.3.235.0 and earlier allow remote attackers to inject arbitrary HTML and web script via the (1) Success Template (STPL) and (2) Failure Template (FTPL) parameters, which are not properly handled in an error message.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 1.57% probability · 74th percentile
- CISA KEV
- Not listed
- Affected
- cisco/meetingplace web confrencing
- Source
- cve@mitre.org
References
- http://lists.grok.org.uk/pipermail/full-disclosure/2007-August/065134.html
- http://secunia.com/advisories/26376
- http://securityreason.com/securityalert/2990
- http://www.cisco.com/en/US/products/products_security_response09186a008089969e.html
- http://www.securityfocus.com/archive/1/475840/100/0/threaded
- http://www.securityfocus.com/archive/1/475845/100/0/threaded
- http://www.securityfocus.com/bid/25237
- http://www.securitytracker.com/id?1018537
- http://www.vupen.com/english/advisories/2007/2815
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35871
- http://lists.grok.org.uk/pipermail/full-disclosure/2007-August/065134.html
- http://secunia.com/advisories/26376
- http://securityreason.com/securityalert/2990
- http://www.cisco.com/en/US/products/products_security_response09186a008089969e.html
- http://www.securityfocus.com/archive/1/475840/100/0/threaded
- http://www.securityfocus.com/archive/1/475845/100/0/threaded
- http://www.securityfocus.com/bid/25237
- http://www.securitytracker.com/id?1018537
- http://www.vupen.com/english/advisories/2007/2815
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35871
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.