Vulnerability CVE-2013-5528


Published: 2013-10-10   Modified: 2013-10-12

Description:
Directory traversal vulnerability in the Tomcat administrative web interface in Cisco Unified Communications Manager allows remote authenticated users to read arbitrary files via directory traversal sequences in an unspecified input string, aka Bug ID CSCui78815.

See advisories in our WLB2 database:
Topic
Author
Date
Med.
Cisco Unified Communications Manager Administrative Web Interface Directory traversal
justpentest
08.12.2016

CVSS2 => (AV:N/AC:L/Au:S/C:P/I:N/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
4/10
2.9/10
8/10
Exploit range
Attack complexity
Authentication
Remote
Low
Single time
Confidentiality impact
Integrity impact
Availability impact
Partial
None
None
Affected software
Cisco -> Unified communications manager 

 References:
http://packetstormsecurity.com/files/140071/Cisco-Unified-Communications-Manager-7-8-9-Directory-Traversal.html
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-5528
http://www.securityfocus.com/bid/62960
https://www.exploit-db.com/exploits/40887/

Copyright 2024, cxsecurity.com

 

Back to Top