MEDIUM
Cross-site scripting (XSS) vulnerability in Cisco CallManager 3.3 before 3.3(5)SR3, 4.1 before 4.1(3)SR4, 4.2 before 4.2(3), and 4.3 before 4.3(1), allows remote attackers to inject arbitrary web script or HTML via the (1) pattern parameter in ccmadmin/phonelist.asp and (2) arbitrary parameters in ccmuser/logon.asp, aka bugid CSCsb68657
Published Jun 21, 2006
4.3
MEDIUMCVSS 2.0
EPSS 13.73%
Description
Cross-site scripting (XSS) vulnerability in Cisco CallManager 3.3 before 3.3(5)SR3, 4.1 before 4.1(3)SR4, 4.2 before 4.2(3), and 4.3 before 4.3(1), allows remote attackers to inject arbitrary web script or HTML via the (1) pattern parameter in ccmadmin/phonelist.asp and (2) arbitrary parameters in ccmuser/logon.asp, aka bugid CSCsb68657.
Affected products
No data.
OR
- 3.3
- 3.3\(3\)
- 3.3\(3\)es61
- 3.3\(4\)es25
- 3.3\(5\)
- 3.3\(5\)es30
- 3.3\(5\)sr1
- 3.3\(5\)sr2
- 4.1
- 4.1\(2\)es33
- 4.1\(2\)es55
- 4.1\(3\)es07
- 4.1\(3\)es32
- 4.1\(3\)sr1
- 4.1\(3\)sr2
- 4.1\(3\)sr3
- 4.2
- 4.2\(1\)
- 4.2\(2\)
- 4.3
- 4.3\(1\)
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (0)
No CWE recorded.
References (13)
- http://lists.grok.org.uk/pipermail/full-disclosure/2006-June/047015.html mailing-listx_refsource_FULLDISC
- http://lists.grok.org.uk/pipermail/full-disclosure/2006-June/047019.html mailing-listx_refsource_FULLDISC
- http://secunia.com/advisories/20735 third-party-advisoryx_refsource_SECUNIA
- http://securityreason.com/securityalert/1114 third-party-advisoryx_refsource_SREASON
- http://securitytracker.com/id?1016328 vdb-entryx_refsource_SECTRACKExploitPatch
- http://www.cisco.com/en/US/products/sw/voicesw/ps556/tsd_products_security_response09186a00806c0846.html vendor-advisoryx_refsource_CISCOPatch
- http://www.fishnetsecurity.com/csirt/disclosure/cisco/Cisco+CallManager+XSS+Advisory.htm x_refsource_MISCExploit
- http://www.osvdb.org/26651 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/26652 vdb-entryx_refsource_OSVDB
- http://www.securityfocus.com/archive/1/437757/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/18504 vdb-entryx_refsource_BIDExploit
- http://www.vupen.com/english/advisories/2006/2443 vdb-entryx_refsource_VUPEN
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27225 vdb-entryx_refsource_XF
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jun 21, 2006
Updated Aug 7, 2024
Reserved Jun 20, 2006
Link CVE-2006-3109
CISA Vulnrichment
Updated n/a