Cisco Unity Connection Web Framework Cross-Site Scripting Vulnerability
Description
(:A cross-site scripting vulnerability was reported in the web framework of Cisco Unity Connection.:A remote attacker could exploit it by enticing their victim into following a specially formed link in order to execute arbitrary JavaScript or HTML code.::This vulnerability is due to insufficient input validation of HTTP GET and POST requests.::Cisco announces that this vulnerability is currently exploited in the wild.)