First published: Mon Oct 13 2008(Updated: )
Cross-site scripting (XSS) vulnerability in Cisco Unity 4.x before 4.2(1)ES162, 5.x before 5.0(1)ES56, and 7.x before 7.0(2)ES8 allows remote authenticated administrators to inject arbitrary web script or HTML by entering it in the database (aka data store).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Unity Server | =5.0 | |
Cisco Unity Server | =4.0 | |
Cisco Unity Server | <=7.0\(2\) | |
Cisco Unity Server | =4.0\(4\)-sr1 | |
Cisco Unity Server | <=4.2\(1\) | |
Cisco Unity Server | =4.0\(3\) | |
Cisco Unity Server | =4.1\(1\) | |
Cisco Unity Server | =4.0\(2\) | |
Cisco Unity Server | =4.0\(5\) | |
Cisco Unity Server | <=5.0\(1\) | |
Cisco Unity Server | =4.0\(4\) | |
Cisco Unity Server | =4.0\(3\)-sr2 | |
Cisco Unity Server | =7.0 | |
Cisco Unity Server | =4.0\(1\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-4542 is considered to have a high severity rating due to its potential for cross-site scripting attacks.
To mitigate CVE-2008-4542, upgrade to the latest version of Cisco Unity that addresses this vulnerability.
CVE-2008-4542 affects Cisco Unity versions 4.x through 7.x prior to their respective fixed releases.
No, CVE-2008-4542 requires remote authenticated administrator access to exploit the vulnerability.
CVE-2008-4542 is classified as a cross-site scripting (XSS) vulnerability.