PoC Index

CVE-2007-4634

HIGH 9.3EPSS 4.3%

Multiple SQL injection vulnerabilities in Cisco CallManager and Unified Communications Manager (CUCM) before 3.3(5)sr2b, 4.1 before 4.1(3)sr5, 4.2 before 4.2(3)sr2, and 4.3 before 4.3(1)sr1 allow remote attackers to execute arbitrary SQL commands via the lang variable to the (1) user or (2) admin logon page, aka CSCsi64265.

CVSS v2.0
9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS
4.31% chance of exploitation in the next 30 days, 90th percentile
Published
2007-08-31
Updated
2024-08-07

ExploitDB entries (1)

References

Related