CVE-2013-4653
Last modified
CVE-2013-4653 is a vulnerability of currently unknown severity. Multiple cross-site scripting (XSS) vulnerabilities in the signin functionality of ics in MyTeamwork services in Alcatel-Lucent Omnitouch 8660 My Teamwork before 6.7, Omnitouch 8670 Automated Message Delivery System (AMDS) before 6.7, Omnitouch 8460 Advanced Communication Server before 9.1, and OmniTouch 8400 Instant Communications Suite before 6.7.3 (1) allow remote attackers to inject arbitrary web script or HTML via a crafted URL that results in a reflected XSS or (2) allow user-assisted remote attackers to inject arbitrary web script or HTML via a user's personal bookmark entry that results in a stored XSS via unspecified vectors.. EPSS estimates a 1.28% chance of exploitation in the next 30 days.
Description
Multiple cross-site scripting (XSS) vulnerabilities in the signin functionality of ics in MyTeamwork services in Alcatel-Lucent Omnitouch 8660 My Teamwork before 6.7, Omnitouch 8670 Automated Message Delivery System (AMDS) before 6.7, Omnitouch 8460 Advanced Communication Server before 9.1, and OmniTouch 8400 Instant Communications Suite before 6.7.3 (1) allow remote attackers to inject arbitrary web script or HTML via a crafted URL that results in a reflected XSS or (2) allow user-assisted remote attackers to inject arbitrary web script or HTML via a user's personal bookmark entry that results in a stored XSS via unspecified vectors.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Alcatel-Lucent | Omnitouch 8400 Instant Communications Suite | <= 6.7.2 |
| Alcatel-Lucent | Omnitouch 8460 Advanced Communication Server | <= 9.0 |
| Alcatel-Lucent | Omnitouch 8660 My Teamwork | <= 6.6 |
| Alcatel-Lucent | Omnitouch 8670 Automated Delivery Message Delivery System | <= 6.6 |
References
- http://secunia.com/advisories/54000Vendor Advisory
- http://secunia.com/advisories/54000Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2013-4653?
How severe is CVE-2013-4653?
How do I fix CVE-2013-4653?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2013
- CVE-2013-4635Integer overflow in the SdnToJewish function in jewish.c in …
- CVE-2013-4636The mget function in libmagic/softmagic.c in the Fileinfo co…
- CVE-2013-4649Cross-site scripting (XSS) vulnerability in DotNetNuke (DNN)…
- CVE-2013-4650MongoDB 2.4.x before 2.4.5 and 2.5.x before 2.5.1 allows rem…
- CVE-2013-4651Siemens Scalance W7xx devices with firmware before 4.5.4 use…
- CVE-2013-4652Unspecified vulnerability in the command-line management int…
- CVE-2013-4654Symlink Traversal vulnerability in TP-LINK TL-WDR4300 and TL…9.8
- CVE-2013-4655Symlink Traversal vulnerability in Belkin N900 due to miscon…7.5
- CVE-2013-4656Symlink Traversal vulnerability in ASUS RT-AC66U and RT-N56U…9.8
- CVE-2013-4657Symlink Traversal vulnerability in NETGEAR WNR3500U and WNR3…9.8
- CVE-2013-4658Linksys EA6500 has SMB Symlink Traversal allowing symbolic l…9.8
- CVE-2013-4659Buffer overflow in Broadcom ACSD allows remote attackers to …
Are you affected by CVE-2013-4653?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
