3.5
CVSSv2

CVE-2009-2048

Published: 16/07/2009 Updated: 17/08/2017
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in the Administration interface in Cisco Customer Response Solutions (CRS) prior to 7.0(1) SR2 in Cisco Unified Contact Center Express (aka CCX) server allows remote authenticated users to inject arbitrary web script or HTML into the CCX database via unspecified vectors.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco crs 7.0

cisco unified ccx 6.0\\(1\\)

cisco unified ccx 5.0\\(1\\)

cisco unified ccx 3.5

cisco unified ip ivr 3.1

cisco unified ip ivr 7.0

cisco unified ip ivr 7.0\\(1\\)

cisco crs 4.1

cisco crs 4.5

cisco unified ccx 4.5\\(2\\)

cisco unified ccx 4.0\\(3\\)

cisco unified ip ivr 4.1

cisco unified ip ivr 4.5

cisco unified ip contact center express 6.0\\(1\\)

cisco unified ip contact center express 7.0

cisco customer response applications 3.5

cisco crs 3.5

cisco crs 4.0

cisco unified ccx 4.0\\(1\\)

cisco unified ccx 4.5\\(1\\)

cisco unified ip ivr 3.0

cisco unified ip ivr 4.0

cisco unified ip contact center express 3.0

cisco unified ip contact center express 5.0\\(1\\)

cisco crs 5.0

cisco crs 6.0

cisco unified ccx 7.0\\(1\\)

cisco unified ccx 4.0\\(5a\\)

cisco unified ccx 4.0\\(5\\)

cisco unified ip ivr 5.0

cisco unified ip ivr 6.0

cisco ip qm 3.5

cisco unified ccx 4.0\\(4\\)