Radvision Scopia Cross Site Scripting Vulnerabilities
26 Aug. 2009
Summary
Radvision's Scopia provides a solution for voice and video collaborative communications. If the web-based interface is exposed to an XSS attack, the index.jsp page does not check the user's input and it is possible to inject arbitrary code into the page parameters. It's also possible to steal user's cookie or other data by sending a maliciously crafted URL to authenticated user.