CVE-2007-1467
published 2007-03-16CVE-2007-1467: Multiple cross-site scripting (XSS) vulnerabilities in (1) PreSearch.html and (2) PreSearch.class in Cisco Secure Access Control Server (ACS), VPN Client…
PriorityP414low3.5CVSS 2.0
AVNACMAuSCNIPAN
EPSS
1.19%
64.4th percentile
Multiple cross-site scripting (XSS) vulnerabilities in (1) PreSearch.html and (2) PreSearch.class in Cisco Secure Access Control Server (ACS), VPN Client, Unified Personal Communicator, MeetingPlace, Unified MeetingPlace, Unified MeetingPlace Express, CallManager, IP Communicator, Unified Video Advantage, Unified Videoconferencing 35xx products, Unified Videoconferencing Manager, WAN Manager, Security Device Manager, Network Analysis Module (NAM), CiscoWorks and related products, Wireless LAN Solution Engine (WLSE), 2006 Wireless LAN Controllers (WLC), and Wireless Control System (WCS) allow remote attackers to inject arbitrary web script or HTML via the text field of the search form.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | acs_solution_engine | — | — |
| cisco | vpn_client | — | — |
| cisco | vpn_client | — | — |
| cisco | vpn_client | — | — |
| cisco | vpn_client | — | — |
| cisco | vpn_client | — | — |
| cisco | vpn_client | — | — |
| cisco | vpn_client | — | — |
| cisco | vpn_client | — | — |
| cisco | vpn_client | — | — |
| cisco | wireless_control_system | — | — |
CVSS provenance
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
vendor_redhat5.0MEDIUM
vendor_cisco3.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Flash plugin DNS rebinding
vendor_redhat·2007-10-08·CVSS 5.0
CVE-2007-5275 [MEDIUM] Flash plugin DNS rebinding
Flash plugin DNS rebinding
The Adobe Macromedia Flash 9 plug-in allows remote attackers to cause a victim machine to establish TCP sessions with arbitrary hosts via a Flash (SWF) movie, related to lack of pinning of a hostname to a single IP address after receiving an allow-access-from element in a cross-domain-policy XML document, and the availability of a Flash Socket class that does not use the browser's DNS pins, aka DNS rebinding attacks, a different issue than CVE-2002-1467 and CVE-2007-4324.
Cisco
Cisco Online Help System Cross-Site Scripting Vulnerability
vendor_cisco·2007-03-15·CVSS 3.5
CVE-2007-1467 [LOW] CWE-79 Cisco Online Help System Cross-Site Scripting Vulnerability
Cisco Online Help System Cross-Site Scripting Vulnerability
Multiple Cisco products contain a vulnerability in the Online Help System that could allow an unauthenticated, remote attacker to conduct cross-site scripting attacks.
This vulnerability exists because the search feature of the web-based Online Help System interface fails to sufficiently filter user-supplied input. An unauthenticated, remote attacker could exploit this vulnerability by convincing a user to follow a crafted link. This action could allow the attacker to execute arbitrary code in a user's browser in the context of the affected site. An exploit could allow the attacker to access sensitive browser information or take actions on the affected site as the targeted user.
Cisco confirmed this vulnerability in a security re
GHSA
GHSA-m8gw-9xmq-cmmc: Multiple cross-site scripting (XSS) vulnerabilities in (1) PreSearch
ghsa_unreviewed·2022-05-01
CVE-2007-1467 [LOW] GHSA-m8gw-9xmq-cmmc: Multiple cross-site scripting (XSS) vulnerabilities in (1) PreSearch
Multiple cross-site scripting (XSS) vulnerabilities in (1) PreSearch.html and (2) PreSearch.class in Cisco Secure Access Control Server (ACS), VPN Client, Unified Personal Communicator, MeetingPlace, Unified MeetingPlace, Unified MeetingPlace Express, CallManager, IP Communicator, Unified Video Advantage, Unified Videoconferencing 35xx products, Unified Videoconferencing Manager, WAN Manager, Security Device Manager, Network Analysis Module (NAM), CiscoWorks and related products, Wireless LAN Solution Engine (WLSE), 2006 Wireless LAN Controllers (WLC), and Wireless Control System (WCS) allow remote attackers to inject arbitrary web script or HTML via the text field of the search form.
No detection rules found.
No public exploits indexed.
http://secunia.com/advisories/24499http://securityreason.com/securityalert/2437http://www.cisco.com/en/US/products/products_security_response09186a0080803fe4.htmlhttp://www.securityfocus.com/archive/1/462932/100/0/threadedhttp://www.securityfocus.com/archive/1/462944/100/0/threadedhttp://www.securityfocus.com/bid/22982http://www.securitytracker.com/id?1017778http://www.vupen.com/english/advisories/2007/0973https://exchange.xforce.ibmcloud.com/vulnerabilities/33024http://secunia.com/advisories/24499http://securityreason.com/securityalert/2437http://www.cisco.com/en/US/products/products_security_response09186a0080803fe4.htmlhttp://www.securityfocus.com/archive/1/462932/100/0/threadedhttp://www.securityfocus.com/archive/1/462944/100/0/threadedhttp://www.securityfocus.com/bid/22982http://www.securitytracker.com/id?1017778http://www.vupen.com/english/advisories/2007/0973https://exchange.xforce.ibmcloud.com/vulnerabilities/33024
2007-03-16
Published