CVE-2009-2048
Summary
| CVE | CVE-2009-2048 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-07-16 15:30:00 UTC |
| Updated | 2017-08-17 01:30:00 UTC |
| Description | Cross-site scripting (XSS) vulnerability in the Administration interface in Cisco Customer Response Solutions (CRS) before 7.0(1) SR2 in Cisco Unified Contact Center Express (aka CCX) server allows remote authenticated users to inject arbitrary web script or HTML into the CCX database via unspecified vectors. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Cisco | Crs | 3.5 | All | All | All |
| Application | Cisco | Crs | 4.0 | All | All | All |
| Application | Cisco | Crs | 4.1 | All | All | All |
| Application | Cisco | Crs | 4.5 | All | All | All |
| Application | Cisco | Crs | 5.0 | All | All | All |
| Application | Cisco | Crs | 6.0 | All | All | All |
| Application | Cisco | Crs | 7.0 | All | All | All |
| Application | Cisco | Crs | 3.5 | All | All | All |
| Application | Cisco | Crs | 4.0 | All | All | All |
| Application | Cisco | Crs | 4.1 | All | All | All |
| Application | Cisco | Crs | 4.5 | All | All | All |
| Application | Cisco | Crs | 5.0 | All | All | All |
| Application | Cisco | Crs | 6.0 | All | All | All |
| Application | Cisco | Crs | 7.0 | All | All | All |
| Application | Cisco | Customer Response Applications | 3.5 | All | All | All |
| Application | Cisco | Customer Response Applications | 3.5 | All | All | All |
| Application | Cisco | Ip Qm | 3.5 | All | All | All |
| Application | Cisco | Ip Qm | 3.5 | All | All | All |
| Application | Cisco | Unified Ccx | 3.5 | All | All | All |
| Application | Cisco | Unified Ccx | 4.0(1) | All | All | All |
| Application | Cisco | Unified Ccx | 4.0(3) | All | All | All |
| Application | Cisco | Unified Ccx | 4.0(4) | All | All | All |
| Application | Cisco | Unified Ccx | 4.0(5) | All | All | All |
| Application | Cisco | Unified Ccx | 4.0(5a) | All | All | All |
| Application | Cisco | Unified Ccx | 4.0\(1\) | All | All | All |
| Application | Cisco | Unified Ccx | 4.0\(3\) | All | All | All |
| Application | Cisco | Unified Ccx | 4.0\(4\) | All | All | All |
| Application | Cisco | Unified Ccx | 4.0\(5a\) | All | All | All |
| Application | Cisco | Unified Ccx | 4.0\(5\) | All | All | All |
| Application | Cisco | Unified Ccx | 4.5(1) | All | All | All |
| Application | Cisco | Unified Ccx | 4.5(2) | All | All | All |
| Application | Cisco | Unified Ccx | 4.5\(1\) | All | All | All |
| Application | Cisco | Unified Ccx | 4.5\(2\) | All | All | All |
| Application | Cisco | Unified Ccx | 5.0(1) | All | All | All |
| Application | Cisco | Unified Ccx | 5.0\(1\) | All | All | All |
| Application | Cisco | Unified Ccx | 6.0(1) | All | All | All |
| Application | Cisco | Unified Ccx | 6.0\(1\) | All | All | All |
| Application | Cisco | Unified Ccx | 7.0(1) | All | All | All |
| Application | Cisco | Unified Ccx | 7.0\(1\) | All | All | All |
| Application | Cisco | Unified Ccx | 3.5 | All | All | All |
| Application | Cisco | Unified Ccx | 4.0\(1\) | All | All | All |
| Application | Cisco | Unified Ccx | 4.0\(3\) | All | All | All |
| Application | Cisco | Unified Ccx | 4.0\(4\) | All | All | All |
| Application | Cisco | Unified Ccx | 4.0\(5a\) | All | All | All |
| Application | Cisco | Unified Ccx | 4.0\(5\) | All | All | All |
| Application | Cisco | Unified Ccx | 4.5\(1\) | All | All | All |
| Application | Cisco | Unified Ccx | 4.5\(2\) | All | All | All |
| Application | Cisco | Unified Ccx | 5.0\(1\) | All | All | All |
| Application | Cisco | Unified Ccx | 6.0\(1\) | All | All | All |
| Application | Cisco | Unified Ccx | 7.0\(1\) | All | All | All |
| Application | Cisco | Unified Ip Contact Center Express | 3.0 | All | All | All |
| Application | Cisco | Unified Ip Contact Center Express | 5.0(1) | All | All | All |
| Application | Cisco | Unified Ip Contact Center Express | 5.0\(1\) | All | All | All |
| Application | Cisco | Unified Ip Contact Center Express | 6.0(1) | All | All | All |
| Application | Cisco | Unified Ip Contact Center Express | 6.0\(1\) | All | All | All |
| Application | Cisco | Unified Ip Contact Center Express | 7.0 | All | All | All |
| Application | Cisco | Unified Ip Contact Center Express | 3.0 | All | All | All |
| Application | Cisco | Unified Ip Contact Center Express | 5.0\(1\) | All | All | All |
| Application | Cisco | Unified Ip Contact Center Express | 6.0\(1\) | All | All | All |
| Application | Cisco | Unified Ip Contact Center Express | 7.0 | All | All | All |
| Application | Cisco | Unified Ip Ivr | 3.0 | All | All | All |
| Application | Cisco | Unified Ip Ivr | 3.1 | All | All | All |
| Application | Cisco | Unified Ip Ivr | 4.0 | All | All | All |
| Application | Cisco | Unified Ip Ivr | 4.1 | All | All | All |
| Application | Cisco | Unified Ip Ivr | 4.5 | All | All | All |
| Application | Cisco | Unified Ip Ivr | 5.0 | All | All | All |
| Application | Cisco | Unified Ip Ivr | 6.0 | All | All | All |
| Application | Cisco | Unified Ip Ivr | 7.0 | All | All | All |
| Application | Cisco | Unified Ip Ivr | 7.0(1) | All | All | All |
| Application | Cisco | Unified Ip Ivr | 7.0\(1\) | All | All | All |
| Application | Cisco | Unified Ip Ivr | 3.0 | All | All | All |
| Application | Cisco | Unified Ip Ivr | 3.1 | All | All | All |
| Application | Cisco | Unified Ip Ivr | 4.0 | All | All | All |
| Application | Cisco | Unified Ip Ivr | 4.1 | All | All | All |
| Application | Cisco | Unified Ip Ivr | 4.5 | All | All | All |
| Application | Cisco | Unified Ip Ivr | 5.0 | All | All | All |
| Application | Cisco | Unified Ip Ivr | 6.0 | All | All | All |
| Application | Cisco | Unified Ip Ivr | 7.0 | All | All | All |
| Application | Cisco | Unified Ip Ivr | 7.0\(1\) | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| Cisco Security Advisory: Vulnerabilities in Unified Contact Center Express Administration Pages - Cisco Systems | CISCO | www.cisco.com | Patch, Vendor Advisory |
| Cisco Unified Contact Center Express (CCX) Arbitrary Script Injection Vulnerability | BID | www.securityfocus.com | |
| Cisco Unified Contact Center Express Two Vulnerabilities - Secunia Advisories - Vulnerability Information - Secunia.com | SECUNIA | secunia.com | |
| Cisco Unified Contact Center Express Express Administration Pages Permit Script Injection and Directory Traversal Attacks - SecurityTracker | SECTRACK | www.securitytracker.com | |
| 55937 | OSVDB | osvdb.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.