CVE-2014-0735
published 2014-02-20CVE-2014-0735: Cross-site scripting (XSS) vulnerability in the IP Manager Assistant (IPMA) interface in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier…
PriorityP422medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.79%
76.1th percentile
Cross-site scripting (XSS) vulnerability in the IP Manager Assistant (IPMA) interface in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCum46470.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_communications_manager | <= 10.0\(1\) | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_cisco4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hcj4-6pg8-xg65: Cross-site scripting (XSS) vulnerability in the IP Manager Assistant (IPMA) interface in Cisco Unified Communications Manager (Unified CM) 10
ghsa_unreviewed·2022-05-17
CVE-2014-0735 [MEDIUM] CWE-79 GHSA-hcj4-6pg8-xg65: Cross-site scripting (XSS) vulnerability in the IP Manager Assistant (IPMA) interface in Cisco Unified Communications Manager (Unified CM) 10
Cross-site scripting (XSS) vulnerability in the IP Manager Assistant (IPMA) interface in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCum46470.
Cisco
Cisco Unified Communications Manager IPMA Reflected Cross-Site Scripting Vulnerability
vendor_cisco·2014-02-19·CVSS 4.3
CVE-2014-0735 [MEDIUM] CWE-79 Cisco Unified Communications Manager IPMA Reflected Cross-Site Scripting Vulnerability
Cisco Unified Communications Manager IPMA Reflected Cross-Site Scripting Vulnerability
A vulnerability in the Cisco IP Manager Assistant (IPMA) interface of
Cisco Unified Communications Manager (Cisco Unified CM) could allow an
unauthenticated, remote attacker to conduct a cross-site scripting (XSS)
attack against a user of the web interface on the affected system.
The vulnerability is due to insufficient input validation. An attacker
could exploit this vulnerability by convincing a user to access a
malicious link.
Cisco has confirmed the vulnerability in a security notice; however, software updates are not available.
To exploit the vulnerability, the attacker may provide a link that directs a user to a malicious site and use misleading language or instructions to persuade the user t
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-0735http://tools.cisco.com/security/center/viewAlert.x?alertId=32912http://www.securityfocus.com/bid/65641http://www.securitytracker.com/id/1029793http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-0735http://tools.cisco.com/security/center/viewAlert.x?alertId=32912http://www.securityfocus.com/bid/65641http://www.securitytracker.com/id/1029793
2014-02-20
Published