CVE-2013-4653
Summary
| CVE | CVE-2013-4653 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2013-08-20 00:48:00 UTC |
| Updated | 2017-08-29 01:33:00 UTC |
| Description | Multiple cross-site scripting (XSS) vulnerabilities in the signin functionality of ics in MyTeamwork services in Alcatel-Lucent Omnitouch 8660 My Teamwork before 6.7, Omnitouch 8670 Automated Message Delivery System (AMDS) before 6.7, Omnitouch 8460 Advanced Communication Server before 9.1, and OmniTouch 8400 Instant Communications Suite before 6.7.3 (1) allow remote attackers to inject arbitrary web script or HTML via a crafted URL that results in a reflected XSS or (2) allow user-assisted remote attackers to inject arbitrary web script or HTML via a user's personal bookmark entry that results in a stored XSS via unspecified vectors. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Alcatel-lucent | Omnitouch 8400 Instant Communications Suite | All | All | All | All |
| Application | Alcatel-lucent | Omnitouch 8460 Advanced Communication Server | All | All | All | All |
| Application | Alcatel-lucent | Omnitouch 8660 My Teamwork | All | All | All | All |
| Application | Alcatel-lucent | Omnitouch 8670 Automated Delivery Message Delivery System | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Page not Found | Nokia | CONFIRM | www3.alcatel-lucent.com | Vendor Advisory |
| 94811 | OSVDB | osvdb.org | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| Security Advisory SA54000 - Alcatel-Lucent OmniTouch Multiple Products Cross-Site Scripting Vulnerability - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| 94810 | OSVDB | osvdb.org | |
| Multiple Alcatel-Lucent OmniTouch Products CVE-2013-4653 Cross Site Scripting Vulnerability | BID | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.