2023-04-24 12:24:31 +02:00
{
"id" : "CVE-2007-1367" ,
"sourceIdentifier" : "cve@mitre.org" ,
"published" : "2007-03-09T22:19:00.000" ,
"lastModified" : "2008-09-05T21:20:18.313" ,
"vulnStatus" : "Analyzed" ,
2024-07-14 02:06:08 +00:00
"cveTags" : [ ] ,
2023-04-24 12:24:31 +02:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "Cross-site scripting (XSS) vulnerability in the login page in Avaya Communications Manager (CM) S87XX, S8500, and S8300 products before 3.1.3 allows remote attackers to inject arbitrary web script or HTML via the Login field."
} ,
{
"lang" : "es" ,
"value" : "Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en la p\u00e1gina de autenticaci\u00f3n de los productos Avaya Communications Manager (CM) S87XX, S8500 y S8300 anteriores al 3.1.3 permite a atacantes remotos inyectar secuencias de comandos web o HTML de su elecci\u00f3n mediante el campo Login."
}
] ,
"metrics" : {
"cvssMetricV2" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "2.0" ,
"vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N" ,
"accessVector" : "NETWORK" ,
"accessComplexity" : "MEDIUM" ,
"authentication" : "NONE" ,
"confidentialityImpact" : "NONE" ,
"integrityImpact" : "PARTIAL" ,
"availabilityImpact" : "NONE" ,
"baseScore" : 4.3
} ,
"baseSeverity" : "MEDIUM" ,
"exploitabilityScore" : 8.6 ,
"impactScore" : 2.9 ,
"acInsufInfo" : false ,
"obtainAllPrivilege" : false ,
"obtainUserPrivilege" : false ,
"obtainOtherPrivilege" : false ,
"userInteractionRequired" : true
}
]
} ,
"weaknesses" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "NVD-CWE-Other"
}
]
}
] ,
"configurations" : [
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:h:avaya:s8710:cm_2.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "80FAA203-5F76-4C21-AC05-57514C431653"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:h:avaya:s8710:cm_3.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "32CD9BFE-4442-4CF0-9139-F9D7F2BC7E58"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:h:avaya:s8710:r2.0.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "68B1272B-8B71-4D2D-A5E4-0E7828500C22"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:h:avaya:s8710:r2.0.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "A7C7B9C0-91A2-4529-B879-60DE043E719C"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:h:avaya:s8300:cm_2.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "4D4D445B-498F-4513-A0F8-49B3E8D2D80A"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:h:avaya:s8300:cm_3.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "CFBC7428-E9E3-444D-908C-124746E673B3"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:h:avaya:s8300:r2.0.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "20C0BD87-CE4B-49D2-89BE-EF282C43AD72"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:h:avaya:s8300:r2.0.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "C3E6C4A8-59F4-43EE-8413-E95289037598"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:h:avaya:s8500:cm_2.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "4D558C4A-8656-47D6-BA5B-4B6BD9A8C6E4"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:h:avaya:s8500:cm_3.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "D421904B-2791-42C8-AAB5-BEAC5F954534"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:h:avaya:s8500:r2.0.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "FE76357A-27E6-4D85-9AA0-1BB658C41568"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:h:avaya:s8500:r2.0.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "C56C5FDB-24E2-479D-87CA-164CD28567D3"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:h:avaya:s8700:cm_2.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "DDDAC89B-F0D4-4373-835F-99AF4F0BCF3F"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:h:avaya:s8700:cm_3.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "0042D294-4AF7-45F5-B356-13B72044D9B4"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:h:avaya:s8700:r2.0.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "AEF6C16F-8EDF-4A24-BFEF-6A304D654EEB"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:h:avaya:s8700:r2.0.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "D982AE39-BB57-49E7-B5FE-5EF1ADE2F019"
}
]
}
]
}
] ,
"references" : [
2024-04-04 08:46:00 +00:00
{
"url" : "http://secunia.com/advisories/24397" ,
"source" : "cve@mitre.org"
} ,
2023-04-24 12:24:31 +02:00
{
"url" : "http://support.avaya.com/elmodocs2/security/ASA-2007-064.htm" ,
"source" : "cve@mitre.org" ,
"tags" : [
"Patch" ,
"Vendor Advisory"
]
} ,
2024-04-04 08:46:00 +00:00
{
"url" : "http://www.osvdb.org/33297" ,
"source" : "cve@mitre.org"
} ,
2023-04-24 12:24:31 +02:00
{
"url" : "http://www.securityfocus.com/bid/22866" ,
"source" : "cve@mitre.org"
}
]
}