4.3
CVSSv2

CVE-2007-1367

Published: 09/03/2007 Updated: 05/09/2008
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in the login page in Avaya Communications Manager (CM) S87XX, S8500, and S8300 products prior to 3.1.3 allows remote malicious users to inject arbitrary web script or HTML via the Login field.

Vulnerable Product Search on Vulmon Subscribe to Product

avaya s8710 cm_2.0

avaya s8710 cm_3.1

avaya s8710 r2.0.0

avaya s8710 r2.0.1

avaya s8300 cm_3.1

avaya s8700 cm_2.0

avaya s8700 r2.0.0

avaya s8300 r2.0.1

avaya s8500 cm_2.0

avaya s8500 cm_3.1

avaya s8500 r2.0.0

avaya s8500 r2.0.1

avaya s8300 cm_2.0

avaya s8300 r2.0.0

avaya s8700 cm_3.1

avaya s8700 r2.0.1