Cross-Site Scripting Vulnerability in Linksys VoIP Phone
CVE-2007-5411
Currently unrated
What is CVE-2007-5411?
The Linksys SPA941 VoIP Phone with firmware version 5.1.8 is vulnerable to a Cross-Site Scripting (XSS) attack. This vulnerability allows remote attackers to inject arbitrary web scripts or HTML, specifically through the From header in a SIP message. If successfully executed, this could enable unauthorized actions to be taken on behalf of legitimate users, potentially leading to further exploitation within the affected network.