CyberSec.Space Logo
CVEブラウザに戻る

CVE-2007-4634

CRITICAL
9.3
CVSS Severity Score
EPSS Score0.1850%
EPSS Percentile16.34th
Published2007年8月31日
Last Modified2026年4月23日

Vulnerability Description

Multiple SQL injection vulnerabilities in Cisco CallManager and Unified Communications Manager (CUCM) before 3.3(5)sr2b, 4.1 before 4.1(3)sr5, 4.2 before 4.2(3)sr2, and 4.3 before 4.3(1)sr1 allow remote attackers to execute arbitrary SQL commands via the lang variable to the (1) user or (2) admin logon page, aka CSCsi64265.

Affected Platforms (CPE)

📦
Cisco

Unified Communications Manager

= 3.3\(5\)
📦
Cisco

Unified Communications Manager

= 3.3\(5\)sr1
📦
Cisco

Unified Communications Manager

= 3.3\(5\)sr2a
📦
Cisco

Unified Communications Manager

= 4.1\(3\)
📦
Cisco

Unified Communications Manager

= 4.1\(3\)sr1
📦
Cisco

Unified Communications Manager

= 4.1\(3\)sr2
📦
Cisco

Unified Communications Manager

= 4.1\(3\)sr3
📦
Cisco

Unified Communications Manager

= 4.1\(3\)sr4
📦
Cisco

Unified Communications Manager

= 4.2
📦
Cisco

Unified Communications Manager

= 4.2.1
📦
Cisco

Unified Communications Manager

= 4.2.2
📦
Cisco

Unified Communications Manager

= 4.2.3
📦
Cisco

Unified Communications Manager

= 4.2.3sr1
📦
Cisco

Unified Communications Manager

= 4.3
📦
Cisco

Unified Communications Manager

= 4.3\(1\)
🔌
Cisco

Call Manager

= 3.3\(5\)sr1
🔌
Cisco

Call Manager

= 3.3\(5\)sr2
🔌
Cisco

Call Manager

= 3.3\(5\)sr2a
🔌
Cisco

Call Manager

= 4.1
🔌
Cisco

Call Manager

= 4.1\(3\)sr1
🔌
Cisco

Call Manager

= 4.1\(3\)sr2
🔌
Cisco

Call Manager

= 4.1\(3\)sr3
🔌
Cisco

Call Manager

= 4.1\(3\)sr4
🔌
Cisco

Call Manager

= 4.2
🔌
Cisco

Call Manager

= 4.2\(1\)
🔌
Cisco

Call Manager

= 4.2\(2\)
🔌
Cisco

Call Manager

= 4.2\(3\)
🔌
Cisco

Call Manager

= 4.2\(3\)sr1
🔌
Cisco

Call Manager

= 4.2\(3\)sr2
🔌
Cisco

Call Manager

= 4.3
🔌
Cisco

Call Manager

= 4.3\(1\)

References & Advisories

関連する脆弱性情報