4.3

CVE-2007-1367

Cross-site scripting (XSS) vulnerability in the login page in Avaya Communications Manager (CM) S87XX, S8500, and S8300 products before 3.1.3 allows remote attackers to inject arbitrary web script or HTML via the Login field.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
AvayaS8710 Versioncm_2.0
AvayaS8710 Versioncm_3.1
AvayaS8710 Versionr2.0.0
AvayaS8710 Versionr2.0.1
AvayaS8300 Versioncm_2.0
AvayaS8300 Versioncm_3.1
AvayaS8300 Versionr2.0.0
AvayaS8300 Versionr2.0.1
AvayaS8500 Versioncm_2.0
AvayaS8500 Versioncm_3.1
AvayaS8500 Versionr2.0.0
AvayaS8500 Versionr2.0.1
AvayaS8700 Versioncm_2.0
AvayaS8700 Versioncm_3.1
AvayaS8700 Versionr2.0.0
AvayaS8700 Versionr2.0.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.29% 0.49
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N