IT

Tracker / CVE-2007-1467

CVE-2007-1467

Low 3.5

Multiple cross-site scripting (XSS) vulnerabilities in (1) PreSearch.html and (2) PreSearch.class in Cisco Secure Access Control Server (ACS), VPN Client, Unified Personal Communicator, MeetingPlace, Unified MeetingPlace, Unified MeetingPlace Express, CallManager, IP Communicator, Unified Video Advantage, Unified Videoconferencing 35xx products, Unified Videoconferencing Manager, WAN Manager, Security Device Manager, Network Analysis Module (NAM), CiscoWorks and related products, Wireless LAN Solution Engine (WLSE), 2006 Wireless LAN Controllers (WLC), and Wireless Control System (WCS) allow remote attackers to inject arbitrary web script or HTML via the text field of the search form.

Affected products and versions

cisco acs_solution_engine
cisco call_manager
cisco ciscoworks
cisco ip_communicator
cisco meetingplace
cisco network_analysis_module
cisco security_device_manager
cisco unified_meetingplace
cisco unified_meetingplace_express
cisco unified_personal_communicator
cisco unified_video_advantage
cisco unified_videoconferencing
cisco unified_videoconferencing_manager
cisco vpn_client
cisco wan_manager
cisco wireless_control_system
cisco wireless_lan_controllers
cisco wireless_lan_solution_engine

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References