HomePentest-Tools.com Logo

Cisco Unified Communications Manager 7/8/9 - Directory Traversal CVE-2013-5528

Severity
CVSSv3 Score
4
Vulnerability description

A directory traversal vulnerability in the Tomcat administrative web interface in Cisco Unified Communications Manager allows remote authenticated users to read arbitrary files via directory traversal sequences in an unspecified input string, aka Bug ID CSCui78815

Risk description

The risk exists that a remote unauthenticated attacker could exploit this vulnerability to read sensitive information from arbitrary files located on the file system of the server.

Recommendation

Apply the necessary security patches or updates provided by Cisco to mitigate this vulnerability.

Codename
Not available
Detectable with
Network Scanner
Scan engine
Nuclei
Exploitable with Sniper
No
CVE Published
Oct 11, 2013
Detection added at
Software Type
Not available
Vendor
Not available
Product
Not available