Sploitus

CVE-2007-2832

1 known exploit for CVE-2007-2832

Cross-site scripting (XSS) vulnerability in the web application firewall in Cisco CallManager before 3.3(5)sr3, 4.1 before 4.1(3)sr5, 4.2 before 4.2(3)sr2, and 4.3 before 4.3(1)sr1 allows remote attackers to inject arbitrary web script or HTML via the pattern parameter to CCMAdmin/serverlist.asp (aka the search-form) and possibly other unspecified vectors.

Affected products
Cisco Callmanager
Cisco Call Manager
= 3.3, 3.3\(3\), 3.3\(3\)es61, 3.3\(4\)es25, 3.3\(5\), 3.3\(5\)es30, 3.3\(5\)sr1, 3.3\(5\)sr2, 4.1, 4.1\(2\)es33, 4.1\(2\)es55, 4.1\(3\)es07, 4.1\(3\)es32, 4.1\(3\)sr1, 4.1\(3\)sr2, 4.1\(3\)sr3, 4.2\(3\), 4.2\(3\)sr1, 4.3\(1\)
Fix
Available
CVSS 2.0
4.3 MEDIUM
EPSS
6.5% (93th percentile)
NVD status
Modified
Published
2007-05-24
CVE-2007-2832 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2007-2832

Proof-of-concept code and exploit modules indexed by Sploitus