Cross-Site Scripting Vulnerabilities in Cisco CallManager and Unified Communications Manager
CVE-2007-4633

Currently unrated

Key Information:

Vendor
Cisco
Vendor
CVE Published:
31 August 2007

Summary

Multiple cross-site scripting vulnerabilities have been identified in Cisco CallManager and Unified Communications Manager. These flaws allow remote attackers to inject arbitrary web scripts or HTML through the 'lang' variable on both user and admin logon pages. This can lead to unauthorized actions performed on behalf of legitimate users, compromising the security integrity of the communication platform.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.