Multiple cross-site scripting (XSS) vulnerabilities in (1) PreSearch.html and (2) PreSearch.class in Cisco Secure Access Control Server (ACS), VPN Client, Unified Personal Communicator, MeetingPlace, Unified MeetingPlace, Unified MeetingPlace Express, CallManager, IP Communicator, Unified Video Advantage, Unified Videoconferencing 35xx products, Unified Videoconferencing Manager, WAN Manager, Security Device Manager, Network Analysis Module (NAM), CiscoWorks and related products, Wireless LAN Solution Engine (WLSE), 2006 Wireless LAN Controllers (WLC), and Wireless Control System (WCS) allow remote attackers to inject arbitrary web script or HTML via the text field of the search form.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Cisco
Subscribe
|
Acs Solution Engine
Subscribe
Call Manager
Subscribe
Ciscoworks
Subscribe
Ip Communicator
Subscribe
Meetingplace
Subscribe
Network Analysis Module
Subscribe
Security Device Manager
Subscribe
Unified Meetingplace
Subscribe
Unified Meetingplace Express
Subscribe
Unified Personal Communicator
Subscribe
Unified Video Advantage
Subscribe
Unified Videoconferencing
Subscribe
Unified Videoconferencing Manager
Subscribe
Vpn Client
Subscribe
Wan Manager
Subscribe
Wireless Control System
Subscribe
Wireless Lan Controllers
Subscribe
Wireless Lan Solution Engine
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2007-1461 | Multiple cross-site scripting (XSS) vulnerabilities in (1) PreSearch.html and (2) PreSearch.class in Cisco Secure Access Control Server (ACS), VPN Client, Unified Personal Communicator, MeetingPlace, Unified MeetingPlace, Unified MeetingPlace Express, CallManager, IP Communicator, Unified Video Advantage, Unified Videoconferencing 35xx products, Unified Videoconferencing Manager, WAN Manager, Security Device Manager, Network Analysis Module (NAM), CiscoWorks and related products, Wireless LAN Solution Engine (WLSE), 2006 Wireless LAN Controllers (WLC), and Wireless Control System (WCS) allow remote attackers to inject arbitrary web script or HTML via the text field of the search form. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T12:59:08.398Z
Reserved: 2007-03-16T00:00:00
Link: CVE-2007-1467
No data.
Status : Deferred
Published: 2007-03-16T21:19:00.000
Modified: 2025-04-09T00:30:58.490
Link: CVE-2007-1467
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD