Cross-Site Scripting Vulnerabilities in Cisco CallManager and Unified Communications Manager
CVE-2007-4633
Currently unrated
Key Information:
- Vendor
- Cisco
- Vendor
- CVE Published:
- 31 August 2007
Summary
Multiple cross-site scripting vulnerabilities have been identified in Cisco CallManager and Unified Communications Manager. These flaws allow remote attackers to inject arbitrary web scripts or HTML through the 'lang' variable on both user and admin logon pages. This can lead to unauthorized actions performed on behalf of legitimate users, compromising the security integrity of the communication platform.
References
Timeline
Vulnerability published
Vulnerability Reserved