CVE-2015-4206
published 2015-12-15CVE-2015-4206: Cisco Unified Communications Manager (UCM) 8.0 through 8.6 allows remote attackers to bypass an XSS protection mechanism via a crafted parameter, aka Bug ID…
PriorityP425medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.86%
77.1th percentile
Cisco Unified Communications Manager (UCM) 8.0 through 8.6 allows remote attackers to bypass an XSS protection mechanism via a crafted parameter, aka Bug ID CSCuu15266.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager_web | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_cisco4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-ppg2-hw6f-p95v: Cisco Unified Communications Manager (UCM) 8
ghsa_unreviewed·2022-05-17
CVE-2015-4206 [MEDIUM] CWE-79 GHSA-ppg2-hw6f-p95v: Cisco Unified Communications Manager (UCM) 8
Cisco Unified Communications Manager (UCM) 8.0 through 8.6 allows remote attackers to bypass an XSS protection mechanism via a crafted parameter, aka Bug ID CSCuu15266.
Cisco
Cisco Unified Communications Manager Web Management Interface Cross-Site Scripting Filter Bypass Vulnerability
vendor_cisco·2015-12-14·CVSS 4.0
CVE-2015-4206 [MEDIUM] CWE-79 Cisco Unified Communications Manager Web Management Interface Cross-Site Scripting Filter Bypass Vulnerability
Cisco Unified Communications Manager Web Management Interface Cross-Site Scripting Filter Bypass Vulnerability
A cross-site scripting (XSS) filter bypass vulnerability in the web management interface of Cisco Unified Communications Manager (UCM) versions 8.0 through 8.6 could allow an unauthenticated, remote attacker to mount XSS attacks against a user of an affected device.
The vulnerability is due to a failure to properly call XSS filter subsystems when a URL contains a certain parameter. An attacker that can convince an authenticated user of an affected device to follow an attacker-provided link or visit an attacker-controlled website could exploit this vulnerability to execute arbitrary code in the context of the affected site on the user's browser.
Cisco has not released software u
Cisco
Cisco Unified Communications Manager Web Management Interface Cross-Site Scripting Filter Bypass Vulnerability
vendor_cisco
CVE-2015-4206 Cisco Unified Communications Manager Web Management Interface Cross-Site Scripting Filter Bypass Vulnerability
CVE-2015-4206: Cisco Unified Communications Manager Web Management Interface Cross-Site Scripting Filter Bypass Vulnerability
A cross-site scripting (XSS) filter bypass vulnerability in the web management interface of Cisco Unified Communications Manager (UCM) versions 8.0 through 8.6 could allow an unauthenticated, remote attacker to mount XSS attacks against a user of an affected device. The vulnerability is due to a failure to properly call XSS filter subsystems when a URL contains a certain parameter. An attacker that can convince an authenticated user of an affected device to follow an attacker-provided link or visit an attacker-controlled website could exploit this vulnerability to execute arbitrary code in the context of the affected site on the user's browser. Cisco has not release
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151214-ucmhttp://www.securityfocus.com/bid/79196http://www.securitytracker.com/id/1034430http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151214-ucmhttp://www.securityfocus.com/bid/79196http://www.securitytracker.com/id/1034430
2015-12-15
Published