CVE-2008-4542
Summary
| CVE | CVE-2008-4542 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2008-10-13 20:00:02 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Cross-site scripting (XSS) vulnerability in Cisco Unity 4.x before 4.2(1)ES162, 5.x before 5.0(1)ES56, and 7.x before 7.0(2)ES8 allows remote authenticated administrators to inject arbitrary web script or HTML by entering it in the database (aka data store). |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
SingleConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:S/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Cisco | Unity | 4.0 | All | All | All |
| Application | Cisco | Unity | 4.0\(1\) | All | All | All |
| Application | Cisco | Unity | 4.0\(2\) | All | All | All |
| Application | Cisco | Unity | 4.0\(3\) | All | All | All |
| Application | Cisco | Unity | 4.0\(3\) | sr2 | All | All |
| Application | Cisco | Unity | 4.0\(4\) | All | All | All |
| Application | Cisco | Unity | 4.0\(4\) | sr1 | All | All |
| Application | Cisco | Unity | 4.0\(5\) | All | All | All |
| Application | Cisco | Unity | 4.1\(1\) | All | All | All |
| Application | Cisco | Unity | 5.0 | All | All | All |
| Application | Cisco | Unity | 7.0 | All | All | All |
| Application | Cisco | Unity | All | All | All | All |
| Application | Cisco | Unity | All | All | All | All |
| Application | Cisco | Unity | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Cisco Unity Input Validation Hole Permits Cross-Site Scripting Attacks - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Cisco Security Response: VoIPshield Reported Vulnerabilities in Cisco Unity Server [Products & Services] - Cisco Systems | af854a3a-2127-422b-91ae-364da2661108 | www.cisco.com | Vendor Advisory |
| Cisco Unity 7.0 Multiple Remote Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Cisco Unity Stored Cross-Site Scripting Vulnerability | Research | VoIPshield Systems Inc. | af854a3a-2127-422b-91ae-364da2661108 | www.voipshield.com | |
| Cisco Unity Script Insertion Vulnerability - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.