Vulnerability Name: | CVE-2007-1367 (CCN-33221) | ||||||||
Assigned: | 2007-03-07 | ||||||||
Published: | 2007-03-07 | ||||||||
Updated: | 2008-09-05 | ||||||||
Summary: | Cross-site scripting (XSS) vulnerability in the login page in Avaya Communications Manager (CM) S87XX, S8500, and S8300 products before 3.1.3 allows remote attackers to inject arbitrary web script or HTML via the Login field. | ||||||||
CVSS v3 Severity: | 3.7 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
2.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:N/A:N/E:H/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2007-1367 Source: CCN Type: SA24397 Avaya Communications Manager Cross-Site Scripting Vulnerability Source: SECUNIA Type: UNKNOWN 24397 Source: CONFIRM Type: Patch, Vendor Advisory http://support.avaya.com/elmodocs2/security/ASA-2007-064.htm Source: CCN Type: Avaya Web site VPNRemote Client Source: OSVDB Type: UNKNOWN 33297 Source: CCN Type: OSVDB ID: 33297 Avaya Communications Manager Login Page XSS Source: BID Type: UNKNOWN 22866 Source: CCN Type: BID-22866 Avaya Communications Manager Javascript Remote Code Execution Vulnerability Source: XF Type: UNKNOWN avayacm-login-xss(33221) | ||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||
BACK |