A vulnerability in the web-based interface of Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against an authenticated user of the interface. This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by persuading an authenticated user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive browser-based information.
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as “..” that can resolve to a location that is outside of that directory.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Unified_communications_manager_im_and_presence_service | Cisco | 10.0(1) (including) | 10.0(1) (including) |
Unified_communications_manager_im_and_presence_service | Cisco | 10.0(1)su1 (including) | 10.0(1)su1 (including) |
Unified_communications_manager_im_and_presence_service | Cisco | 10.0(1)su2 (including) | 10.0(1)su2 (including) |
Unified_communications_manager_im_and_presence_service | Cisco | 10.5(1) (including) | 10.5(1) (including) |
Unified_communications_manager_im_and_presence_service | Cisco | 10.5(1)su1 (including) | 10.5(1)su1 (including) |
Unified_communications_manager_im_and_presence_service | Cisco | 10.5(1)su2 (including) | 10.5(1)su2 (including) |
Unified_communications_manager_im_and_presence_service | Cisco | 10.5(1)su3 (including) | 10.5(1)su3 (including) |
Unified_communications_manager_im_and_presence_service | Cisco | 10.5(2) (including) | 10.5(2) (including) |
Unified_communications_manager_im_and_presence_service | Cisco | 10.5(2)su1 (including) | 10.5(2)su1 (including) |
Unified_communications_manager_im_and_presence_service | Cisco | 10.5(2)su2 (including) | 10.5(2)su2 (including) |
Unified_communications_manager_im_and_presence_service | Cisco | 10.5(2)su2a (including) | 10.5(2)su2a (including) |
Unified_communications_manager_im_and_presence_service | Cisco | 10.5(2)su3 (including) | 10.5(2)su3 (including) |
Unified_communications_manager_im_and_presence_service | Cisco | 10.5(2)su4 (including) | 10.5(2)su4 (including) |
Unified_communications_manager_im_and_presence_service | Cisco | 10.5(2)su4a (including) | 10.5(2)su4a (including) |
Unified_communications_manager_im_and_presence_service | Cisco | 10.5(2a) (including) | 10.5(2a) (including) |
Unified_communications_manager_im_and_presence_service | Cisco | 10.5(2b) (including) | 10.5(2b) (including) |
Unified_communications_manager_im_and_presence_service | Cisco | 11.0(1) (including) | 11.0(1) (including) |
Unified_communications_manager_im_and_presence_service | Cisco | 11.0(1)su1 (including) | 11.0(1)su1 (including) |
Unified_communications_manager_im_and_presence_service | Cisco | 11.5(1) (including) | 11.5(1) (including) |
Unified_communications_manager_im_and_presence_service | Cisco | 11.5(1)su1 (including) | 11.5(1)su1 (including) |
Unified_communications_manager_im_and_presence_service | Cisco | 11.5(1)su2 (including) | 11.5(1)su2 (including) |
Unified_communications_manager_im_and_presence_service | Cisco | 11.5(1)su3 (including) | 11.5(1)su3 (including) |
Unified_communications_manager_im_and_presence_service | Cisco | 11.5(1)su3a (including) | 11.5(1)su3a (including) |
Unified_communications_manager_im_and_presence_service | Cisco | 11.5(1)su4 (including) | 11.5(1)su4 (including) |
Unified_communications_manager_im_and_presence_service | Cisco | 11.5(1)su5 (including) | 11.5(1)su5 (including) |
Unified_communications_manager_im_and_presence_service | Cisco | 11.5(1)su5a (including) | 11.5(1)su5a (including) |
Unified_communications_manager_im_and_presence_service | Cisco | 11.5(1)su6 (including) | 11.5(1)su6 (including) |
Unified_communications_manager_im_and_presence_service | Cisco | 11.5(1)su7 (including) | 11.5(1)su7 (including) |
Unified_communications_manager_im_and_presence_service | Cisco | 11.5(1)su8 (including) | 11.5(1)su8 (including) |
Unified_communications_manager_im_and_presence_service | Cisco | 11.5(1)su9 (including) | 11.5(1)su9 (including) |
Unified_communications_manager_im_and_presence_service | Cisco | 11.5(1)su10 (including) | 11.5(1)su10 (including) |
Unified_communications_manager_im_and_presence_service | Cisco | 11.5(1)su11 (including) | 11.5(1)su11 (including) |
Unified_communications_manager_im_and_presence_service | Cisco | 12.5(1) (including) | 12.5(1) (including) |
Unified_communications_manager_im_and_presence_service | Cisco | 12.5(1)su1 (including) | 12.5(1)su1 (including) |
Unified_communications_manager_im_and_presence_service | Cisco | 12.5(1)su2 (including) | 12.5(1)su2 (including) |
Unified_communications_manager_im_and_presence_service | Cisco | 12.5(1)su3 (including) | 12.5(1)su3 (including) |
Unified_communications_manager_im_and_presence_service | Cisco | 12.5(1)su4 (including) | 12.5(1)su4 (including) |
Unified_communications_manager_im_and_presence_service | Cisco | 12.5(1)su5 (including) | 12.5(1)su5 (including) |
Unified_communications_manager_im_and_presence_service | Cisco | 12.5(1)su6 (including) | 12.5(1)su6 (including) |
Unified_communications_manager_im_and_presence_service | Cisco | 12.5(1)su7 (including) | 12.5(1)su7 (including) |
Unified_communications_manager_im_and_presence_service | Cisco | 14.0 (including) | 14.0 (including) |
Unified_communications_manager_im_and_presence_service | Cisco | 14.0su1 (including) | 14.0su1 (including) |
Unified_communications_manager_im_and_presence_service | Cisco | 14.0su2 (including) | 14.0su2 (including) |
Unified_communications_manager_im_and_presence_service | Cisco | 14.0su2a (including) | 14.0su2a (including) |