CVE-2007-1467
Summary
| CVE | CVE-2007-1467 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2007-03-16 21:19:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Multiple cross-site scripting (XSS) vulnerabilities in (1) PreSearch.html and (2) PreSearch.class in Cisco Secure Access Control Server (ACS), VPN Client, Unified Personal Communicator, MeetingPlace, Unified MeetingPlace, Unified MeetingPlace Express, CallManager, IP Communicator, Unified Video Advantage, Unified Videoconferencing 35xx products, Unified Videoconferencing Manager, WAN Manager, Security Device Manager, Network Analysis Module (NAM), CiscoWorks and related products, Wireless LAN Solution Engine (WLSE), 2006 Wireless LAN Controllers (WLC), and Wireless Control System (WCS) allow remote attackers to inject arbitrary web script or HTML via the text field of the search form. |
Risk And Classification
Primary CVSS: v2.0 3.5 from [email protected]
AV:N/AC:M/Au:S/C:N/I:P/A:N
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
SingleConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:S/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Cisco | Acs Solution Engine | 4.1 | All | All | All |
| Application | Cisco | Acs Solution Engine | 4.1 | All | windows | All |
| Hardware | Cisco | Call Manager | All | All | All | All |
| Application | Cisco | Ciscoworks | All | All | All | All |
| Application | Cisco | Ip Communicator | All | All | All | All |
| Application | Cisco | Meetingplace | All | All | All | All |
| Hardware | Cisco | Network Analysis Module | All | All | All | All |
| Application | Cisco | Security Device Manager | All | All | All | All |
| Application | Cisco | Unified Meetingplace | All | All | All | All |
| Application | Cisco | Unified Meetingplace Express | All | All | All | All |
| Application | Cisco | Unified Personal Communicator | All | All | All | All |
| Application | Cisco | Unified Videoconferencing | All | All | All | All |
| Application | Cisco | Unified Videoconferencing Manager | All | All | All | All |
| Application | Cisco | Unified Video Advantage | All | All | All | All |
| Application | Cisco | Vpn Client | 3.5.1 | All | linux | All |
| Application | Cisco | Vpn Client | 3.5.1 | All | solaris | All |
| Application | Cisco | Vpn Client | 3.5.2 | All | linux | All |
| Application | Cisco | Vpn Client | 3.5.2 | All | mac_os_x | All |
| Application | Cisco | Vpn Client | 3.5.2 | All | solaris | All |
| Application | Cisco | Vpn Client | 3.5.2b | All | linux | All |
| Application | Cisco | Vpn Client | 3.5.2b | All | mac_os_x | All |
| Application | Cisco | Vpn Client | 3.5.2b | All | solaris | All |
| Application | Cisco | Vpn Client | 3.5.4 | All | linux | All |
| Application | Cisco | Vpn Client | 3.5.4 | All | mac_os_x | All |
| Application | Cisco | Vpn Client | 3.5.4 | All | solaris | All |
| Application | Cisco | Vpn Client | 3.6 | All | linux | All |
| Application | Cisco | Vpn Client | 3.6 | All | mac_os_x | All |
| Application | Cisco | Vpn Client | 3.6 | All | solaris | All |
| Application | Cisco | Vpn Client | 3.6.1 | All | linux | All |
| Application | Cisco | Vpn Client | 3.6.1 | All | mac_os_x | All |
| Application | Cisco | Vpn Client | 3.6.1 | All | solaris | All |
| Application | Cisco | Vpn Client | 4.0.2a | All | mac_os_x | All |
| Application | Cisco | Vpn Client | 4.0.2a | All | solaris | All |
| Application | Cisco | Vpn Client | 4.0.2c | All | mac_os_x | All |
| Application | Cisco | Vpn Client | 4.0.2c | All | solaris | All |
| Application | Cisco | Vpn Client | 4.8.1 | All | windows | All |
| Application | Cisco | Wan Manager | All | All | All | All |
| Hardware | Cisco | Wireless Control System | 4.0 | All | All | All |
| Application | Cisco | Wireless Lan Controllers | All | All | All | All |
| Application | Cisco | Wireless Lan Solution Engine | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Cisco Multiple Products Online Help System Cross-Site Scripting - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| SecurityReason - XSS vulnerability in the online help system of several Cisco products | af854a3a-2127-422b-91ae-364da2661108 | securityreason.com | |
| Cisco Security Response: Cross-Site Scripting Vulnerability in Online Help System [Products & Services] - Cisco Systems | af854a3a-2127-422b-91ae-364da2661108 | www.cisco.com | Vendor Advisory |
| Cisco Online Help System Input Validation Hole Permits Cross-Site Scripting Attacks Against Several Cisco Products - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Multiple Cisco Products Online Help Cross Site Scripting Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.