CVE-2007-1467

Severity

35%

Complexity

68%

Confidentiality

48%

Multiple cross-site scripting (XSS) vulnerabilities in (1) PreSearch.html and (2) PreSearch.class in Cisco Secure Access Control Server (ACS), VPN Client, Unified Personal Communicator, MeetingPlace, Unified MeetingPlace, Unified MeetingPlace Express, CallManager, IP Communicator, Unified Video Advantage, Unified Videoconferencing 35xx products, Unified Videoconferencing Manager, WAN Manager, Security Device Manager, Network Analysis Module (NAM), CiscoWorks and related products, Wireless LAN Solution Engine (WLSE), 2006 Wireless LAN Controllers (WLC), and Wireless Control System (WCS) allow remote attackers to inject arbitrary web script or HTML via the text field of the search form.

Multiple cross-site scripting (XSS) vulnerabilities in (1) PreSearch.html and (2) PreSearch.class in Cisco Secure Access Control Server (ACS), VPN Client, Unified Personal Communicator, MeetingPlace, Unified MeetingPlace, Unified MeetingPlace Express, CallManager, IP Communicator, Unified Video Advantage, Unified Videoconferencing 35xx products, Unified Videoconferencing Manager, WAN Manager, Security Device Manager, Network Analysis Module (NAM), CiscoWorks and related products, Wireless LAN Solution Engine (WLSE), 2006 Wireless LAN Controllers (WLC), and Wireless Control System (WCS) allow remote attackers to inject arbitrary web script or HTML via the text field of the search form.

CVSS 2.0 Base Score 3.5. CVSS Attack Vector: network. CVSS Attack Complexity: medium. CVSS Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:N).

Overview

Type

Cisco

First reported 17 years ago

2007-03-16 21:19:00

Last updated 6 years ago

2018-10-16 16:38:00

Affected Software

Cisco ACS Solution Engine 4.1

4.1

Cisco CiscoWorks

Cisco IP Communicator

Cisco MeetingPlace

Cisco Adaptive Security Appliance (ASA) Device Manager

Cisco Unified MeetingPlace

Cisco Unified MeetingPlace Express

Cisco Unified Personal Communicator

Cisco Unified Video Advantage

Cisco Unified Videoconferencing

Cisco Unified Videoconferencing Manager

Cisco WAN Manager

Cisco 2006 Wireless LAN Controllers

Cisco Wireless LAN Solution Engine

Cisco Call Manager

Cisco Network Analysis Module

Cisco Wireless Control System 4.0

4.0

Stay updated

ExploitPedia is constantly evolving. Sign up to receive a notification when we release additional functionality.

Get in touch

If you'd like to report a bug or have any suggestions for improvements then please do get in touch with us using this form. We will get back to you as soon as we can.