4.3
CVSSv2

CVE-2014-3324

Published: 26/07/2014 Updated: 29/08/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in the login page in the administrative web interface in Cisco TelePresence Server Software 4.0(2.8) allow remote malicious users to inject arbitrary web script or HTML via a crafted parameter, aka Bug ID CSCup90060.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco telepresence server software 4.0\\(2.8\\)

cisco telepresence server software 4.0\\(1.57\\)

cisco telepresence server software 3.1\\(1.98\\)

cisco telepresence server software 3.0\\(2.24\\)

Vendor Advisories

The Cisco TelePresence administrative web interface login page contains a vulnerability that could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the user of the web interface of the affected system The vulnerability is due to insufficient input validation of certain parameters passed using HTTP G ...