Cisco Unified Communications Manager Administrative Web Interface Directory Traversal Vulnerability
Description
(#A directory traversal vulnerability has been reported in the web interface of Cisco Unified Communications Manager.#A remote authenticated attacker could exploit it to obtain an arbitrary file via a specially formed HTTP request.#Updated, 07/12/2016:#This vulnerability is exploitable via the "fileName" parameter of the "ccmadmin/bulkvivewfilecontents.do?filetype=samplefile" web page.##A proof of concept is available.)