CVE-2012-4970: XSS
Cross-site scripting (XSS) vulnerability in the web management interface on Polycom HDX Video End Points with UC APL software before 2.7.1.1J, and commercial software before 3.0.5, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-4970?
CVE-2012-4970 has a medium severity rating because it allows for cross-site scripting (XSS) vulnerabilities that could be exploited by remote attackers.
How do I fix CVE-2012-4970?
To fix CVE-2012-4970, update the Polycom HDX Video End Points to the latest version of UC APL software that is 2.7.1.1_J or later.
What systems are affected by CVE-2012-4970?
CVE-2012-4970 affects Polycom HDX Video End Points running UC APL software versions prior to 2.7.1.1_J and commercial software before 3.0.5.
What type of attack is CVE-2012-4970 associated with?
CVE-2012-4970 is associated with cross-site scripting (XSS) attacks that allow attackers to inject arbitrary web scripts or HTML.
Can I exploit CVE-2012-4970 without user interaction?
Yes, CVE-2012-4970 can potentially be exploited remotely without requiring user interaction, allowing an attacker to execute malicious scripts.