3.5
CVSSv2

CVE-2007-1467

Published: 16/03/2007 Updated: 16/10/2018
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in (1) PreSearch.html and (2) PreSearch.class in Cisco Secure Access Control Server (ACS), VPN Client, Unified Personal Communicator, MeetingPlace, Unified MeetingPlace, Unified MeetingPlace Express, CallManager, IP Communicator, Unified Video Advantage, Unified Videoconferencing 35xx products, Unified Videoconferencing Manager, WAN Manager, Security Device Manager, Network Analysis Module (NAM), CiscoWorks and related products, Wireless LAN Solution Engine (WLSE), 2006 Wireless LAN Controllers (WLC), and Wireless Control System (WCS) allow remote malicious users to inject arbitrary web script or HTML via the text field of the search form.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco unified meetingplace express

cisco unified personal communicator

cisco vpn client 3.5.2

cisco vpn client 3.6.1

cisco vpn client 4.0.2c

cisco vpn client 4.8.1

cisco acs solution engine 4.1

cisco ciscoworks

cisco unified video advantage

cisco unified videoconferencing

cisco vpn client 3.5.2b

cisco vpn client 3.6

cisco wan manager

cisco wireless lan controllers

cisco security device manager

cisco unified meetingplace

cisco vpn client 3.5.1

cisco vpn client 3.5.4

cisco vpn client 4.0.2a

cisco network analysis module

cisco wireless control system 4.0

cisco ip communicator

cisco meetingplace

cisco unified videoconferencing manager

cisco wireless lan solution engine

cisco call manager