{ "id": "CVE-2007-5547", "sourceIdentifier": "cve@mitre.org", "published": "2007-10-18T20:17:00.000", "lastModified": "2025-04-09T00:30:58.490", "vulnStatus": "Deferred", "cveTags": [], "descriptions": [ { "lang": "en", "value": "Cross-site scripting (XSS) vulnerability in Cisco IOS allows remote attackers to inject arbitrary web script or HTML, and execute IOS commands, via unspecified vectors, aka PSIRT-2022590358. NOTE: as of 20071016, the only disclosure is a vague pre-advisory with no actionable information. However, since it is from a well-known researcher, it is being assigned a CVE identifier for tracking purposes." }, { "lang": "es", "value": "Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en Cisco IOS permite a atacantes remotos inyectar secuencias de comandos web o HTML de su elecci\u00f3n, y ejecutar comandos IOS, a trav\u00e9s de vectores no especificados, tambi\u00e9n conocida como PSIRT-2022590358. NOTA: a fecha de 16/10/2007, la \u00fanica revelaci\u00f3n es un vago preaviso sin informaci\u00f3n de uso inmediato. Sin embargo, dado que proviene de un investigador reputado, se le ha asignado un identificador CVE con prop\u00f3sito de seguimiento." } ], "metrics": { "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N", "baseScore": 4.3, "accessVector": "NETWORK", "accessComplexity": "MEDIUM", "authentication": "NONE", "confidentialityImpact": "NONE", "integrityImpact": "PARTIAL", "availabilityImpact": "NONE" }, "baseSeverity": "MEDIUM", "exploitabilityScore": 8.6, "impactScore": 2.9, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "CWE-79" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:o:cisco:ios:*:*:*:*:*:*:*:*", "matchCriteriaId": "5802E2D8-7069-474C-826F-AEE7B50BFE34" } ] } ] } ], "references": [ { "url": "http://osvdb.org/43742", "source": "cve@mitre.org" }, { "url": "http://www.irmplc.com/index.php/111-Vendor-Alerts", "source": "cve@mitre.org" }, { "url": "http://osvdb.org/43742", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "http://www.irmplc.com/index.php/111-Vendor-Alerts", "source": "af854a3a-2127-422b-91ae-364da2661108" } ] }