Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
146377 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.106441
Categoría:CISCO
Título:Cisco Unified Communications Manager Administration Page Cross-Site Scripting Vulnerability (cisco-sa-20161207-cucm)
Resumen:A vulnerability in the ccmadmin page of Cisco Unified; Communications Manager (CUCM) could allow an unauthenticated, remote attacker to conduct; reflected cross-site scripting (XSS) attacks.
Descripción:Summary:
A vulnerability in the ccmadmin page of Cisco Unified
Communications Manager (CUCM) could allow an unauthenticated, remote attacker to conduct
reflected cross-site scripting (XSS) attacks.

Vulnerability Insight:
The vulnerability is due to improper sanitization or encoding
of user-supplied data by the ccmadmin page of an affected version of CUCM. An attacker could
exploit this vulnerability by persuading a targeted user to follow a malicious link.

Vulnerability Impact:
An exploit could allow the attacker to conduct a reflected XSS
attack.

Affected Software/OS:
Cisco Unified Communications Manager version 11.5(1.10000.6).

Solution:
See the referenced vendor advisory for a solution.

CVSS Score:
4.3

CVSS Vector:
AV:N/AC:M/Au:N/C:N/I:P/A:N

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2016-9206
BugTraq ID: 94793
http://www.securityfocus.com/bid/94793
http://www.securitytracker.com/id/1037424
CopyrightCopyright (C) 2016 Greenbone AG

Esta es sólo una de 146377 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.