CVE-2007-2832
Summary
| CVE | CVE-2007-2832 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2007-05-24 02:30:00 UTC |
| Updated | 2017-07-29 01:31:00 UTC |
| Description | Cross-site scripting (XSS) vulnerability in the web application firewall in Cisco CallManager before 3.3(5)sr3, 4.1 before 4.1(3)sr5, 4.2 before 4.2(3)sr2, and 4.3 before 4.3(1)sr1 allows remote attackers to inject arbitrary web script or HTML via the pattern parameter to CCMAdmin/serverlist.asp (aka the search-form) and possibly other unspecified vectors. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Cisco | Call Manager | 3.3 | All | All | All |
| Hardware | Cisco | Call Manager | 3.3(3) | All | All | All |
| Hardware | Cisco | Call Manager | 3.3(3)es61 | All | All | All |
| Hardware | Cisco | Call Manager | 3.3(4)es25 | All | All | All |
| Hardware | Cisco | Call Manager | 3.3(5) | All | All | All |
| Hardware | Cisco | Call Manager | 3.3(5)es30 | All | All | All |
| Hardware | Cisco | Call Manager | 3.3(5)sr1 | All | All | All |
| Hardware | Cisco | Call Manager | 3.3(5)sr2 | All | All | All |
| Hardware | Cisco | Call Manager | 3.3\(3\) | All | All | All |
| Hardware | Cisco | Call Manager | 3.3\(3\)es61 | All | All | All |
| Hardware | Cisco | Call Manager | 3.3\(4\)es25 | All | All | All |
| Hardware | Cisco | Call Manager | 3.3\(5\) | All | All | All |
| Hardware | Cisco | Call Manager | 3.3\(5\)es30 | All | All | All |
| Hardware | Cisco | Call Manager | 3.3\(5\)sr1 | All | All | All |
| Hardware | Cisco | Call Manager | 3.3\(5\)sr2 | All | All | All |
| Hardware | Cisco | Call Manager | 4.1 | All | All | All |
| Hardware | Cisco | Call Manager | 4.1(2)es33 | All | All | All |
| Hardware | Cisco | Call Manager | 4.1(2)es55 | All | All | All |
| Hardware | Cisco | Call Manager | 4.1(3)es07 | All | All | All |
| Hardware | Cisco | Call Manager | 4.1(3)es32 | All | All | All |
| Hardware | Cisco | Call Manager | 4.1(3)sr1 | All | All | All |
| Hardware | Cisco | Call Manager | 4.1(3)sr2 | All | All | All |
| Hardware | Cisco | Call Manager | 4.1(3)sr3 | All | All | All |
| Hardware | Cisco | Call Manager | 4.1\(2\)es33 | All | All | All |
| Hardware | Cisco | Call Manager | 4.1\(2\)es55 | All | All | All |
| Hardware | Cisco | Call Manager | 4.1\(3\)es07 | All | All | All |
| Hardware | Cisco | Call Manager | 4.1\(3\)es32 | All | All | All |
| Hardware | Cisco | Call Manager | 4.1\(3\)sr1 | All | All | All |
| Hardware | Cisco | Call Manager | 4.1\(3\)sr2 | All | All | All |
| Hardware | Cisco | Call Manager | 4.1\(3\)sr3 | All | All | All |
| Hardware | Cisco | Call Manager | 4.2(3) | All | All | All |
| Hardware | Cisco | Call Manager | 4.2(3)sr1 | All | All | All |
| Hardware | Cisco | Call Manager | 4.2\(3\) | All | All | All |
| Hardware | Cisco | Call Manager | 4.2\(3\)sr1 | All | All | All |
| Hardware | Cisco | Call Manager | 4.3(1) | All | All | All |
| Hardware | Cisco | Call Manager | 4.3\(1\) | All | All | All |
| Hardware | Cisco | Call Manager | 3.3 | All | All | All |
| Hardware | Cisco | Call Manager | 3.3\(3\) | All | All | All |
| Hardware | Cisco | Call Manager | 3.3\(3\)es61 | All | All | All |
| Hardware | Cisco | Call Manager | 3.3\(4\)es25 | All | All | All |
| Hardware | Cisco | Call Manager | 3.3\(5\) | All | All | All |
| Hardware | Cisco | Call Manager | 3.3\(5\)es30 | All | All | All |
| Hardware | Cisco | Call Manager | 3.3\(5\)sr1 | All | All | All |
| Hardware | Cisco | Call Manager | 3.3\(5\)sr2 | All | All | All |
| Hardware | Cisco | Call Manager | 4.1 | All | All | All |
| Hardware | Cisco | Call Manager | 4.1\(2\)es33 | All | All | All |
| Hardware | Cisco | Call Manager | 4.1\(2\)es55 | All | All | All |
| Hardware | Cisco | Call Manager | 4.1\(3\)es07 | All | All | All |
| Hardware | Cisco | Call Manager | 4.1\(3\)es32 | All | All | All |
| Hardware | Cisco | Call Manager | 4.1\(3\)sr1 | All | All | All |
| Hardware | Cisco | Call Manager | 4.1\(3\)sr2 | All | All | All |
| Hardware | Cisco | Call Manager | 4.1\(3\)sr3 | All | All | All |
| Hardware | Cisco | Call Manager | 4.2\(3\) | All | All | All |
| Hardware | Cisco | Call Manager | 4.2\(3\)sr1 | All | All | All |
| Hardware | Cisco | Call Manager | 4.3\(1\) | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| scip AG [Security - Consulting - Information - Process] | MISC | www.scip.ch | |
| Cisco CallManager Search Form Cross Site Scripting Vulnerability | BID | www.securityfocus.com | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| 35337 | OSVDB | www.osvdb.org | |
| Cisco CallManager Cross-Site Scripting Vulnerability - Advisories - Secunia | SECUNIA | secunia.com | Patch, Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| Cisco CallManager Input Validation Vulnerability - Cisco Systems | CISCO | www.cisco.com | |
| '[Full-disclosure] Cisco CallManager 4.1 Input Validation' - MARC | FULLDISC | marc.info | Exploit, Vendor Advisory |
| Cisco CallManager Input Validation Hole in Search Form Permits Cross-Site Scripting Attacks - SecurityTracker | SECTRACK | www.securitytracker.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.