CVE-2007-4633
published 2007-08-31CVE-2007-4633: Multiple cross-site scripting (XSS) vulnerabilities in Cisco CallManager and Unified Communications Manager (CUCM) before 3.3(5)sr2b, 4.1 before 4.1(3)sr5, 4.2…
PriorityP415medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.22%
65.2th percentile
Multiple cross-site scripting (XSS) vulnerabilities in Cisco CallManager and Unified Communications Manager (CUCM) before 3.3(5)sr2b, 4.1 before 4.1(3)sr5, 4.2 before 4.2(3)sr2, and 4.3 before 4.3(1)sr1 allow remote attackers to inject arbitrary web script or HTML via the lang variable to the (1) user or (2) admin logon page, aka CSCsi10728.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | call_manager | — | — |
| cisco | call_manager | — | — |
| cisco | call_manager | — | — |
| cisco | call_manager | — | — |
| cisco | call_manager | — | — |
| cisco | call_manager | — | — |
| cisco | call_manager | — | — |
| cisco | call_manager | — | — |
| cisco | call_manager | — | — |
| cisco | call_manager | — | — |
| cisco | call_manager | — | — |
| cisco | call_manager | — | — |
| cisco | call_manager | — | — |
| cisco | call_manager | — | — |
| cisco | call_manager | — | — |
| cisco | call_manager | — | — |
| cisco | call_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_cisco5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
XSS and SQL Injection in Cisco CallManager/Unified Communications Manager Logon Page
vendor_cisco·2007-08-29·CVSS 5.0
CVE-2007-4633 [MEDIUM] CWE-200 XSS and SQL Injection in Cisco CallManager/Unified Communications Manager Logon Page
XSS and SQL Injection in Cisco CallManager/Unified Communications Manager Logon Page
Cisco CallManager and Unified Communications Manager are vulnerable to
cross-site Scripting (XSS) and SQL Injection attacks in the lang variable of
the admin and user logon pages. A successful attack may allow an attacker to
run JavaScript on computer systems connecting to CallManager or Unified
Communications Manager servers, and has the potential to disclose information
within the database.
Cisco has made free software available to address these vulnerabilities
for affected customers.
This advisory is posted at
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20070829-ccm.
Cisco
XSS and SQL Injection in Cisco CallManager/Unified Communications Manager Logon Page
vendor_cisco
CVE-2007-4633 XSS and SQL Injection in Cisco CallManager/Unified Communications Manager Logon Page
CVE-2007-4633: XSS and SQL Injection in Cisco CallManager/Unified Communications Manager Logon Page
Cisco CallManager and Unified Communications Manager are vulnerable to cross-site Scripting (XSS) and SQL Injection attacks in the lang variable of the admin and user logon pages. A successful attack may allow an attacker to run JavaScript on computer systems connecting to CallManager or Unified Communications Manager servers, and has the potential to disclose information within the database. Cisco has made free software available to address these vulnerabilities for affected customers. This advisory is posted at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20070829-ccm .
CWE: CWE-200, CWE-79, CWE-200, CWE-79
Bug IDs: CSCsi10728, CSCsi64265, CSCsi107
GHSA
GHSA-89hr-m868-h7qm: Multiple cross-site scripting (XSS) vulnerabilities in Cisco CallManager and Unified Communications Manager (CUCM) before 3
ghsa_unreviewed·2022-05-01
CVE-2007-4633 [MEDIUM] CWE-79 GHSA-89hr-m868-h7qm: Multiple cross-site scripting (XSS) vulnerabilities in Cisco CallManager and Unified Communications Manager (CUCM) before 3
Multiple cross-site scripting (XSS) vulnerabilities in Cisco CallManager and Unified Communications Manager (CUCM) before 3.3(5)sr2b, 4.1 before 4.1(3)sr5, 4.2 before 4.2(3)sr2, and 4.3 before 4.3(1)sr1 allow remote attackers to inject arbitrary web script or HTML via the lang variable to the (1) user or (2) admin logon page, aka CSCsi10728.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/26641http://securitytracker.com/id?1018624http://www.cisco.com/en/US/products/products_security_advisory09186a00808ae327.shtmlhttp://www.securityfocus.com/bid/25480http://www.vupen.com/english/advisories/2007/3010https://exchange.xforce.ibmcloud.com/vulnerabilities/36325http://secunia.com/advisories/26641http://securitytracker.com/id?1018624http://www.cisco.com/en/US/products/products_security_advisory09186a00808ae327.shtmlhttp://www.securityfocus.com/bid/25480http://www.vupen.com/english/advisories/2007/3010https://exchange.xforce.ibmcloud.com/vulnerabilities/36325
2007-08-31
Published