CVE-2013-4653
Last modified
CVE-2013-4653 is a vulnerability of currently unknown severity. Multiple cross-site scripting (XSS) vulnerabilities in the signin functionality of ics in MyTeamwork services in Alcatel-Lucent Omnitouch 8660 My Teamwork before 6.7, Omnitouch 8670 Automated Message Delivery System (AMDS) before 6.7, Omnitouch 8460 Advanced Communication Server before 9.1, and OmniTouch 8400 Instant Communications Suite before 6.7.3 (1) allow remote attackers to inject arbitrary web script or HTML via a crafted URL that results in a reflected XSS or (2) allow user-assisted remote attackers to inject arbitrary web script or HTML via a user's personal bookmark entry that results in a stored XSS via unspecified vectors.. EPSS estimates a 1.28% chance of exploitation in the next 30 days.
Description
Multiple cross-site scripting (XSS) vulnerabilities in the signin functionality of ics in MyTeamwork services in Alcatel-Lucent Omnitouch 8660 My Teamwork before 6.7, Omnitouch 8670 Automated Message Delivery System (AMDS) before 6.7, Omnitouch 8460 Advanced Communication Server before 9.1, and OmniTouch 8400 Instant Communications Suite before 6.7.3 (1) allow remote attackers to inject arbitrary web script or HTML via a crafted URL that results in a reflected XSS or (2) allow user-assisted remote attackers to inject arbitrary web script or HTML via a user's personal bookmark entry that results in a stored XSS via unspecified vectors.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Alcatel-Lucent | Omnitouch 8400 Instant Communications Suite | <= 6.7.2 |
| Alcatel-Lucent | Omnitouch 8460 Advanced Communication Server | <= 9.0 |
| Alcatel-Lucent | Omnitouch 8660 My Teamwork | <= 6.6 |
| Alcatel-Lucent | Omnitouch 8670 Automated Delivery Message Delivery System | <= 6.6 |
References
- http://secunia.com/advisories/54000Vendor Advisory
- http://secunia.com/advisories/54000Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2013-4653?
How severe is CVE-2013-4653?
How do I fix CVE-2013-4653?
Are you affected by CVE-2013-4653?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
