CVE-2007-4634
Multiple SQL injection vulnerabilities in Cisco CallManager and Unified Communications Manager (CUCM) before 3.3(5)sr2b, 4.1 before 4.1(3)sr5, 4.2 before 4.2(3)sr2, and 4.3 before 4.3(1)sr1 allow remote attackers to execute arbitrary SQL commands via the lang variable to the (1) user or (2) admin logon page, aka CSCsi64265.
- Affected products
- Cisco Callmanager, Cisco Unified Communications Manager
- Cisco Unified Communications Manager
- = 3.3\(5\), 3.3\(5\)sr1, 3.3\(5\)sr2a, 4.1\(3\), 4.1\(3\)sr1, 4.1\(3\)sr2, 4.1\(3\)sr3, 4.1\(3\)sr4, 4.2, 4.2.1, 4.2.2, 4.2.3, 4.2.3sr1, 4.3, 4.3\(1\)
- Cisco Call Manager
- = 3.3\(5\)sr1, 3.3\(5\)sr2, 3.3\(5\)sr2a, 4.1, 4.1\(3\)sr1, 4.1\(3\)sr2, 4.1\(3\)sr3, 4.1\(3\)sr4, 4.2, 4.2\(1\), 4.2\(2\), 4.2\(3\), 4.2\(3\)sr1, 4.2\(3\)sr2, 4.3, 4.3\(1\)
- Fix
- Available
- CVSS 2.0
- 9.3 HIGH
- EPSS
- 4.3% (90th percentile)
- Weakness
- CWE-89
- NVD status
- Modified
- Published
- 2007-08-31
CVE-2007-4634 at NVD
1 known exploit for CVE-2007-4634
Proof-of-concept code and exploit modules indexed by Sploitus