First published: Thu May 24 2007(Updated: )
Cross-site scripting (XSS) vulnerability in the web application firewall in Cisco CallManager before 3.3(5)sr3, 4.1 before 4.1(3)sr5, 4.2 before 4.2(3)sr2, and 4.3 before 4.3(1)sr1 allows remote attackers to inject arbitrary web script or HTML via the pattern parameter to CCMAdmin/serverlist.asp (aka the search-form) and possibly other unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco CallManager Express | =3.3 | |
Cisco CallManager Express | =3.3\(3\) | |
Cisco CallManager Express | =3.3\(3\)es61 | |
Cisco CallManager Express | =3.3\(4\)es25 | |
Cisco CallManager Express | =3.3\(5\) | |
Cisco CallManager Express | =3.3\(5\)es30 | |
Cisco CallManager Express | =3.3\(5\)sr1 | |
Cisco CallManager Express | =3.3\(5\)sr2 | |
Cisco CallManager Express | =4.1 | |
Cisco CallManager Express | =4.1\(2\)es33 | |
Cisco CallManager Express | =4.1\(2\)es55 | |
Cisco CallManager Express | =4.1\(3\)es07 | |
Cisco CallManager Express | =4.1\(3\)es32 | |
Cisco CallManager Express | =4.1\(3\)sr1 | |
Cisco CallManager Express | =4.1\(3\)sr2 | |
Cisco CallManager Express | =4.1\(3\)sr3 | |
Cisco CallManager Express | =4.2\(3\) | |
Cisco CallManager Express | =4.2\(3\)sr1 | |
Cisco CallManager Express | =4.3\(1\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2007-2832 is classified as medium due to the potential for remote code execution via cross-site scripting.
To mitigate CVE-2007-2832, upgrade to the recommended patched version of Cisco CallManager as listed in the security advisory.
CVE-2007-2832 affects Cisco CallManager versions 3.3(5)sr2, 4.1 before 4.1(3)sr5, 4.2 before 4.2(3)sr2, and 4.3 before 4.3(1)sr1.
Yes, CVE-2007-2832 can be exploited remotely by attackers through specially crafted HTTP requests.
Symptoms of CVE-2007-2832 exploitation may include unauthorized content injection in the web application interface and unexpected behavior of the Cisco CallManager.