>> Cisco CallManager Multiple Cross Site Scripting and SQL Injection Vulnerabilities
Title : Cisco CallManager Multiple Cross Site Scripting and SQL Injection Vulnerabilities VUPEN ID : VUPEN/ADV-2007-3010 CVE ID : CVE-2007-4633 - CVE-2007-4634
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-08-30
Technical Description
Multiple vulnerabilities have been identified in Cisco CallManager and Unified Communications Manager, which could be exploited by remote attackers to execute arbitrary SQL queries or scripting code. These issues are caused by unspecified input validation errors in various scripts when processing user-supplied data, which could be exploited by malicious people to conduct SQL injection or cross site scripting attacks.