CVE-2007-4633

Cisco CallManager/CUCM <3.3.5sr2b-4.3.1sr1 - XSS

Title source: llm

Description

Multiple cross-site scripting (XSS) vulnerabilities in Cisco CallManager and Unified Communications Manager (CUCM) before 3.3(5)sr2b, 4.1 before 4.1(3)sr5, 4.2 before 4.2(3)sr2, and 4.3 before 4.3(1)sr1 allow remote attackers to inject arbitrary web script or HTML via the lang variable to the (1) user or (2) admin logon page, aka CSCsi10728.

Scores

EPSS 0.0055
EPSS Percentile 67.7%

Classification

CWE
CWE-79
Status draft

Affected Products (19)

cisco/unified_communications_manager
cisco/unified_communications_manager
cisco/call_manager
cisco/call_manager
cisco/call_manager
cisco/call_manager
cisco/call_manager
cisco/call_manager
cisco/call_manager
cisco/call_manager
cisco/call_manager
cisco/call_manager
cisco/call_manager
cisco/call_manager
cisco/call_manager
... and 4 more

Timeline

Published Aug 31, 2007
Tracked Since Feb 18, 2026