Description
|
|
(:A cross-site scripting vulnerability was reported in Cisco Unified Email Interaction Manager and Unified Web Interaction Manager.:A remote attacker could exploit it by enticing their victim into following a specially crafted link in order to execute arbitrary JavaScript or HTML code.::This vulnerability stems from insufficient sanitization of user-supplied input.::Cisco announces that a private exploitation code exists.)
|
|
|
|
Vulnerable Products
|
|
Vulnerable OS: Unified Web and E-Mail Interaction Manager (Cisco) - 11.0(1)
|
|
|
|
Solution
|
|
Cisco has released new versions for Unified Email Interaction Manager and Unified Web Interaction Manager which fix this vulnerability.
|
|
|
|
CVE
|
|
CVE-2015-6416
|
|
|
|
References
|
|
- CSCuw24479 : Cisco Unified Email Interaction Manager and Cisco Unified Web Interaction Manager XSS Vulnerability
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151210-uim
|
|
|
|
Vulnerability Manager Detection
|
|
No
|
|
|
|
IPS Protection
|
|
|
|
|
|