← Back

CVE-2007-4633

nvd nist
Published: Aug 31, 2007Modified: Apr 23, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

Multiple cross-site scripting (XSS) vulnerabilities in Cisco CallManager and Unified Communications Manager (CUCM) before 3.3(5)sr2b, 4.1 before 4.1(3)sr5, 4.2 before 4.2(3)sr2, and 4.3 before 4.3(1)sr1 allow remote attackers to inject arbitrary web script or HTML via the lang variable to the (1) user or (2) admin logon page, aka CSCsi10728.

Affected (19)

2 products
Call Manager
Unified Communications Manager
Configuration A
19 vulnerable
Vulnerable SoftwareAffected Versions
Cisco
Version 3.3(5)sr1
Version 3.3(5)sr2
Version 3.3(5)sr2a
Version 4.1
Version 4.1(3)sr1
Version 4.1(3)sr2
Version 4.1(3)sr3
Version 4.1(3)sr4
Version 4.2
Version 4.2(1)
Version 4.2(2)
Version 4.2(3)
Version 4.2(3)sr1
Version 4.2(3)sr2
Version 4.3
Version 4.3(1)
Version 4.3(1)sr1
Cisco
Version 4.2.3sr2
Version 4.2.3sr2b

References (12)

Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.