CVE-2008-2165
Description
Cross-site scripting (XSS) vulnerability in AccessCodeStart.asp in Cisco Building Broadband Service Manager (BBSM) Captive Portal 5.3 allows remote attackers to inject arbitrary web script or HTML via the msg parameter.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Cross-site scripting (XSS) vulnerability in Cisco BBSM Captive Portal 5.3 via the msg parameter in AccessCodeStart.asp allows remote attackers to inject arbitrary web script or HTML.
Vulnerability
The vulnerability is a cross-site scripting (XSS) issue in the AccessCodeStart.asp page of Cisco Building Broadband Service Manager (BBSM) Captive Portal version 5.3. The msg parameter is not properly sanitized, allowing remote attackers to inject arbitrary web script or HTML [1][2].
Exploitation
An attacker can exploit this vulnerability remotely without authentication, though the attack complexity is medium (likely requiring user interaction such as clicking a crafted link). The attacker crafts a malicious URL containing the payload in the msg parameter and lures a victim to visit it [2].
Impact
Successful exploitation results in partial integrity impact (e.g., defacement or phishing) but no confidentiality or availability impact, as per the CVSS score [2]. The attacker can execute arbitrary script in the victim's browser within the context of the vulnerable site.
Mitigation
No specific mitigation is provided in the available references [1][2]. Given the age of the vulnerability (2008), Cisco BBSM Captive Portal 5.3 is likely end-of-life; users should consult Cisco for any remaining guidance or upgrade to a supported solution.
AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- cpe:2.3:a:cisco:building_broadband_service_manager:5.3:*:*:*:*:*:*:*
- Range: =5.3
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- secunia.com/advisories/30222nvdVendor Advisory
- securityreason.com/securityalert/3895nvd
- securitytracker.com/idnvd
- www.securityfocus.com/archive/1/492043/100/0/threadednvd
- www.securityfocus.com/archive/1/492093/100/0/threadednvd
- www.securityfocus.com/bid/29191nvd
- www.vupen.com/english/advisories/2008/1535nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/42395nvd
News mentions
0No linked articles in our index yet.