CVE-2013-1224
published 2013-05-09CVE-2013-1224: Directory traversal vulnerability in the Resource Manager in Cisco Unified Customer Voice Portal (CVP) Software before 9.0.1 ES 11 allows remote attackers to…
PriorityP345high7.8CVSS 2.0
AVNACLAuNCNICAN
EPSS
2.12%
79.7th percentile
Directory traversal vulnerability in the Resource Manager in Cisco Unified Customer Voice Portal (CVP) Software before 9.0.1 ES 11 allows remote attackers to overwrite arbitrary files via a crafted (1) HTTP or (2) HTTPS request that triggers incorrect parameter validation, aka Bug ID CSCub38369.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_customer_voice_portal | <= 9.0\(1\) | — |
| cisco | unified_customer_voice_portal | — | — |
| cisco | unified_customer_voice_portal | — | — |
| cisco | unified_customer_voice_portal | — | — |
| cisco | unified_customer_voice_portal | — | — |
| cisco | unified_customer_voice_portal | — | — |
| cisco | unified_customer_voice_portal | — | — |
| cisco | unified_customer_voice_portal | — | — |
| cisco | unified_customer_voice_portal | — | — |
| cisco | unified_customer_voice_portal | — | — |
| cisco | unified_customer_voice_portal | — | — |
| cisco | unified_customer_voice_portal | — | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:C/A:N
vendor_cisco10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Multiple Vulnerabilities in Cisco Unified Customer Voice Portal Software
vendor_cisco·2013-05-08·CVSS 10.0
CVE-2013-1220 [CRITICAL] CWE-119 Multiple Vulnerabilities in Cisco Unified Customer Voice Portal Software
Multiple Vulnerabilities in Cisco Unified Customer Voice Portal Software
Cisco Unified Customer Voice Portal Software (Unified CVP) contains multiple vulnerabilities. Various components of Cisco Unified CVP are affected; see the "Details" section for more information on the vulnerabilities. These vulnerabilities can be exploited independently; however, more than one vulnerability could be exploited on the same device.
Cisco has released software updates that address these vulnerabilities. Workarounds that mitigate some of these vulnerabilities are available.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130508-cvp
Cisco
Multiple Vulnerabilities in Cisco Unified Customer Voice Portal Software
vendor_cisco
CVE-2013-1224 Multiple Vulnerabilities in Cisco Unified Customer Voice Portal Software
CVE-2013-1224: Multiple Vulnerabilities in Cisco Unified Customer Voice Portal Software
Cisco Unified Customer Voice Portal Software (Unified CVP) contains multiple vulnerabilities. Various components of Cisco Unified CVP are affected; see the "
CWE: CWE-119, CWE-16, CWE-200, CWE-119, CWE-16, CWE-200, CWE-22, CWE-119, CWE-16, CWE-200, CWE-119, CWE-16, CWE-200, CWE-22
Bug IDs: CSCua65148, CSCub38366, CSCub38369, CSCua65148, CSCub38366
GHSA
GHSA-94x3-94ph-mg4c: Directory traversal vulnerability in the Resource Manager in Cisco Unified Customer Voice Portal (CVP) Software before 9
ghsa_unreviewed·2022-05-17
CVE-2013-1224 [HIGH] CWE-22 GHSA-94x3-94ph-mg4c: Directory traversal vulnerability in the Resource Manager in Cisco Unified Customer Voice Portal (CVP) Software before 9
Directory traversal vulnerability in the Resource Manager in Cisco Unified Customer Voice Portal (CVP) Software before 9.0.1 ES 11 allows remote attackers to overwrite arbitrary files via a crafted (1) HTTP or (2) HTTPS request that triggers incorrect parameter validation, aka Bug ID CSCub38369.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2013-05-09
Published