cbcvebase.
CVE-2007-4633
published 2007-08-31

CVE-2007-4633: Multiple cross-site scripting (XSS) vulnerabilities in Cisco CallManager and Unified Communications Manager (CUCM) before 3.3(5)sr2b, 4.1 before 4.1(3)sr5, 4.2…

PriorityP415medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.22%
65.2th percentile
Multiple cross-site scripting (XSS) vulnerabilities in Cisco CallManager and Unified Communications Manager (CUCM) before 3.3(5)sr2b, 4.1 before 4.1(3)sr5, 4.2 before 4.2(3)sr2, and 4.3 before 4.3(1)sr1 allow remote attackers to inject arbitrary web script or HTML via the lang variable to the (1) user or (2) admin logon page, aka CSCsi10728.

Affected

19 ranges
VendorProductVersion rangeFixed in
ciscocall_manager
ciscocall_manager
ciscocall_manager
ciscocall_manager
ciscocall_manager
ciscocall_manager
ciscocall_manager
ciscocall_manager
ciscocall_manager
ciscocall_manager
ciscocall_manager
ciscocall_manager
ciscocall_manager
ciscocall_manager
ciscocall_manager
ciscocall_manager
ciscocall_manager
ciscounified_communications_manager
ciscounified_communications_manager

CVSS provenance

nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_cisco5.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.