Sploitus

CVE-2007-4634

1 known exploit for CVE-2007-4634

Multiple SQL injection vulnerabilities in Cisco CallManager and Unified Communications Manager (CUCM) before 3.3(5)sr2b, 4.1 before 4.1(3)sr5, 4.2 before 4.2(3)sr2, and 4.3 before 4.3(1)sr1 allow remote attackers to execute arbitrary SQL commands via the lang variable to the (1) user or (2) admin logon page, aka CSCsi64265.

Cisco Unified Communications Manager
= 3.3\(5\), 3.3\(5\)sr1, 3.3\(5\)sr2a, 4.1\(3\), 4.1\(3\)sr1, 4.1\(3\)sr2, 4.1\(3\)sr3, 4.1\(3\)sr4, 4.2, 4.2.1, 4.2.2, 4.2.3, 4.2.3sr1, 4.3, 4.3\(1\)
Cisco Call Manager
= 3.3\(5\)sr1, 3.3\(5\)sr2, 3.3\(5\)sr2a, 4.1, 4.1\(3\)sr1, 4.1\(3\)sr2, 4.1\(3\)sr3, 4.1\(3\)sr4, 4.2, 4.2\(1\), 4.2\(2\), 4.2\(3\), 4.2\(3\)sr1, 4.2\(3\)sr2, 4.3, 4.3\(1\)
Fix
Available
CVSS 2.0
9.3 HIGH
EPSS
4.3% (90th percentile)
Weakness
CWE-89
NVD status
Modified
Published
2007-08-31
CVE-2007-4634 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2007-4634

Proof-of-concept code and exploit modules indexed by Sploitus