CVE Database
/

CVE-2011-2544

Back to search

CVE-2011-2544

Published: Sep 23, 2011

Modified: Aug 6, 2024

PUBLISHED

Description

Cross-site scripting (XSS) vulnerability in the web interface in Cisco TelePresence System MXP Series F9.1 and earlier allows remote authenticated users to inject arbitrary web script or HTML via a crafted Call ID, as demonstrated by resultant cross-site request forgery (CSRF) attacks that change passwords or cause a denial of service, aka Bug ID CSCtq46488.

VendorProductVersions

n/a

n/a

affected
n/a

References

49670
vdb-entry
x_refsource_BID
8393
third-party-advisory
x_refsource_SREASON
46057
third-party-advisory
x_refsource_SECUNIA
46109
third-party-advisory
x_refsource_SECUNIA
1026072
vdb-entry
x_refsource_SECTRACK
17871
exploit
x_refsource_EXPLOIT-DB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now