← All CVEs

CVE-2006-3109

medium · 4.3

Cross-site scripting (XSS) vulnerability in Cisco CallManager 3.3 before 3.3(5)SR3, 4.1 before 4.1(3)SR4, 4.2 before 4.2(3), and 4.3 before 4.3(1), allows remote attackers to inject arbitrary web script or HTML via the (1) pattern parameter in ccmadmin/phonelist.asp and (2) arbitrary parameters in ccmuser/logon.asp, aka bugid CSCsb68657.

4.3
CVSS
13.7%
EPSS (exploit prob.)
96th
EPSS percentile
2006-06-21
Published

AV:N/AC:M/Au:N/C:N/I:P/A:N

Affected products

VendorProductAffected versions
ciscocall_manager3.3
ciscocall_manager3.3(3)
ciscocall_manager3.3(3)es61
ciscocall_manager3.3(4)es25
ciscocall_manager3.3(5)
ciscocall_manager3.3(5)es30
ciscocall_manager3.3(5)sr1
ciscocall_manager3.3(5)sr2
ciscocall_manager4.1
ciscocall_manager4.1(2)es33
ciscocall_manager4.1(2)es55
ciscocall_manager4.1(3)es07
ciscocall_manager4.1(3)es32
ciscocall_manager4.1(3)sr1
ciscocall_manager4.1(3)sr2
ciscocall_manager4.1(3)sr3
ciscocall_manager4.2
ciscocall_manager4.2(1)
ciscocall_manager4.2(2)
ciscocall_manager4.3
ciscocall_manager4.3(1)

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2006-3109