CVE-2006-3109
Summary
| CVE | CVE-2006-3109 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-06-21 01:02:00 UTC |
| Updated | 2018-10-18 16:45:00 UTC |
| Description | Cross-site scripting (XSS) vulnerability in Cisco CallManager 3.3 before 3.3(5)SR3, 4.1 before 4.1(3)SR4, 4.2 before 4.2(3), and 4.3 before 4.3(1), allows remote attackers to inject arbitrary web script or HTML via the (1) pattern parameter in ccmadmin/phonelist.asp and (2) arbitrary parameters in ccmuser/logon.asp, aka bugid CSCsb68657. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Cisco | Call Manager | 3.3 | All | All | All |
| Hardware | Cisco | Call Manager | 3.3(3) | All | All | All |
| Hardware | Cisco | Call Manager | 3.3(3)es61 | All | All | All |
| Hardware | Cisco | Call Manager | 3.3(4)es25 | All | All | All |
| Hardware | Cisco | Call Manager | 3.3(5) | All | All | All |
| Hardware | Cisco | Call Manager | 3.3(5)es30 | All | All | All |
| Hardware | Cisco | Call Manager | 3.3(5)sr1 | All | All | All |
| Hardware | Cisco | Call Manager | 3.3(5)sr2 | All | All | All |
| Hardware | Cisco | Call Manager | 3.3\(3\) | All | All | All |
| Hardware | Cisco | Call Manager | 3.3\(3\)es61 | All | All | All |
| Hardware | Cisco | Call Manager | 3.3\(4\)es25 | All | All | All |
| Hardware | Cisco | Call Manager | 3.3\(5\) | All | All | All |
| Hardware | Cisco | Call Manager | 3.3\(5\)es30 | All | All | All |
| Hardware | Cisco | Call Manager | 3.3\(5\)sr1 | All | All | All |
| Hardware | Cisco | Call Manager | 3.3\(5\)sr2 | All | All | All |
| Hardware | Cisco | Call Manager | 4.1 | All | All | All |
| Hardware | Cisco | Call Manager | 4.1(2)es33 | All | All | All |
| Hardware | Cisco | Call Manager | 4.1(2)es55 | All | All | All |
| Hardware | Cisco | Call Manager | 4.1(3)es07 | All | All | All |
| Hardware | Cisco | Call Manager | 4.1(3)es32 | All | All | All |
| Hardware | Cisco | Call Manager | 4.1(3)sr1 | All | All | All |
| Hardware | Cisco | Call Manager | 4.1(3)sr2 | All | All | All |
| Hardware | Cisco | Call Manager | 4.1(3)sr3 | All | All | All |
| Hardware | Cisco | Call Manager | 4.1\(2\)es33 | All | All | All |
| Hardware | Cisco | Call Manager | 4.1\(2\)es55 | All | All | All |
| Hardware | Cisco | Call Manager | 4.1\(3\)es07 | All | All | All |
| Hardware | Cisco | Call Manager | 4.1\(3\)es32 | All | All | All |
| Hardware | Cisco | Call Manager | 4.1\(3\)sr1 | All | All | All |
| Hardware | Cisco | Call Manager | 4.1\(3\)sr2 | All | All | All |
| Hardware | Cisco | Call Manager | 4.1\(3\)sr3 | All | All | All |
| Hardware | Cisco | Call Manager | 4.2 | All | All | All |
| Hardware | Cisco | Call Manager | 4.2(1) | All | All | All |
| Hardware | Cisco | Call Manager | 4.2(2) | All | All | All |
| Hardware | Cisco | Call Manager | 4.2\(1\) | All | All | All |
| Hardware | Cisco | Call Manager | 4.2\(2\) | All | All | All |
| Hardware | Cisco | Call Manager | 4.3 | All | All | All |
| Hardware | Cisco | Call Manager | 4.3(1) | All | All | All |
| Hardware | Cisco | Call Manager | 4.3\(1\) | All | All | All |
| Hardware | Cisco | Call Manager | 3.3 | All | All | All |
| Hardware | Cisco | Call Manager | 3.3\(3\) | All | All | All |
| Hardware | Cisco | Call Manager | 3.3\(3\)es61 | All | All | All |
| Hardware | Cisco | Call Manager | 3.3\(4\)es25 | All | All | All |
| Hardware | Cisco | Call Manager | 3.3\(5\) | All | All | All |
| Hardware | Cisco | Call Manager | 3.3\(5\)es30 | All | All | All |
| Hardware | Cisco | Call Manager | 3.3\(5\)sr1 | All | All | All |
| Hardware | Cisco | Call Manager | 3.3\(5\)sr2 | All | All | All |
| Hardware | Cisco | Call Manager | 4.1 | All | All | All |
| Hardware | Cisco | Call Manager | 4.1\(2\)es33 | All | All | All |
| Hardware | Cisco | Call Manager | 4.1\(2\)es55 | All | All | All |
| Hardware | Cisco | Call Manager | 4.1\(3\)es07 | All | All | All |
| Hardware | Cisco | Call Manager | 4.1\(3\)es32 | All | All | All |
| Hardware | Cisco | Call Manager | 4.1\(3\)sr1 | All | All | All |
| Hardware | Cisco | Call Manager | 4.1\(3\)sr2 | All | All | All |
| Hardware | Cisco | Call Manager | 4.1\(3\)sr3 | All | All | All |
| Hardware | Cisco | Call Manager | 4.2 | All | All | All |
| Hardware | Cisco | Call Manager | 4.2\(1\) | All | All | All |
| Hardware | Cisco | Call Manager | 4.2\(2\) | All | All | All |
| Hardware | Cisco | Call Manager | 4.3 | All | All | All |
| Hardware | Cisco | Call Manager | 4.3\(1\) | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Cisco Response to: Input Validation/Output Encoding Vulnerabilities in Cisco CallManager Allow Script Injection Attacks [Cisco Unified Communications Manager] - Cisco Systems | CISCO | www.cisco.com | Patch |
| UltraDNS Client Redirection Service | MISC | www.fishnetsecurity.com | Exploit |
| 26652 | OSVDB | www.osvdb.org | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| [Full-disclosure] Input Validation/Output Encoding Vulnerabilities in Cisco CallManager Allow Script Injection Attacks | FULLDISC | lists.grok.org.uk | |
| [Full-disclosure] Re: Input Validation/Output Encoding Vulnerabilities in Cisco CallManager Allow Script Injection Attacks | FULLDISC | lists.grok.org.uk | |
| Cisco CallManager Cross-Site Scripting Vulnerability | BID | www.securityfocus.com | Exploit |
| SecurityTracker.com Archives - Cisco CallManager 'Administration' and 'User Options' Input Validation Holes Permit Cross-Site Scripting Attacks | SECTRACK | securitytracker.com | Exploit, Patch |
| SecurityReason - Input Validation/Output Encoding Vulnerabilities in Cisco CallManager Allow Script Injection Attacks | SREASON | securityreason.com | |
| 26651 | OSVDB | www.osvdb.org | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| Secunia - Advisories - Cisco CallManager Web Interface Cross-Site Scripting Vulnerabilities | SECUNIA | secunia.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.