Cross-Site Scripting Vulnerability in Cisco CallManager Web Application Firewall
CVE-2007-2832

Currently unrated

Key Information:

Vendor

Cisco

Vendor
CVE Published:
24 May 2007

What is CVE-2007-2832?

The vulnerability in Cisco CallManager's web application firewall allows attackers to exploit the system by injecting arbitrary web scripts or HTML. This can occur via specially crafted requests to the CCMAdmin interface, particularly through the pattern parameter on the serverlist.asp page. If exploited, this vulnerability could be used for a variety of malicious activities, including session hijacking or redirecting users to malicious sites. Organizations using affected versions of Cisco CallManager are urged to apply mitigations and updates to safeguard against potential exploitation.

References

EPSS Score

18% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2007-2832 : Cross-Site Scripting Vulnerability in Cisco CallManager Web Application Firewall