CVE-2016-1377
published 2016-04-12CVE-2016-1377: Cross-site scripting (XSS) vulnerability in Cisco Unity Connection through 11.0 allows remote attackers to inject arbitrary web script or HTML via unspecified…
PriorityP424medium6.1CVSS 3.0
AVNACLPRNUIRSCCLILAN
EPSS
1.01%
59.5th percentile
Cross-site scripting (XSS) vulnerability in Cisco Unity Connection through 11.0 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug ID CSCus21776.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unity_connection | — | — |
| cisco | unity_connection | — | — |
| cisco | unity_connection | — | — |
| cisco | unity_connection | — | — |
| cisco | unity_connection | — | — |
| cisco | unity_connection | — | — |
| cisco | unity_connection | — | — |
CVSS provenance
nvdv3.06.1MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_cisco4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xhjc-54vq-qjm9: Cross-site scripting (XSS) vulnerability in Cisco Unity Connection through 11
ghsa_unreviewed·2022-05-17
CVE-2016-1377 [MEDIUM] CWE-79 GHSA-xhjc-54vq-qjm9: Cross-site scripting (XSS) vulnerability in Cisco Unity Connection through 11
Cross-site scripting (XSS) vulnerability in Cisco Unity Connection through 11.0 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug ID CSCus21776.
Cisco
Cisco Unity Connection Cross-Site Scripting Vulnerability
vendor_cisco·2016-04-13·CVSS 4.3
CVE-2016-1377 [MEDIUM] CWE-79 Cisco Unity Connection Cross-Site Scripting Vulnerability
Cisco Unity Connection Cross-Site Scripting Vulnerability
A vulnerability in the web framework of Cisco Unity Connection could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the user of the web interface of the affected system.
The vulnerability is due to insufficient input validation of certain parameters passed via HTTP GET or POST methods. An attacker who can convince a user to follow an attacker-supplied link could cause arbitrary script or HTML code to be executed on the user's browser in the context of the affected site.
Cisco has released software updates that address this vulnerability. Workarounds that mitigate this vulnerability are not available.
This advisory is available at the following link: https://sec.cloudapps.cisco.co
Cisco
Cisco Unity Connection Cross-Site Scripting Vulnerability
vendor_cisco
CVE-2016-1377 Cisco Unity Connection Cross-Site Scripting Vulnerability
CVE-2016-1377: Cisco Unity Connection Cross-Site Scripting Vulnerability
A vulnerability in the web framework of Cisco Unity Connection could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the user of the web interface of the affected system. The vulnerability is due to insufficient input validation of certain parameters passed via HTTP GET or POST methods. An attacker who can convince a user to follow an attacker-supplied link could cause arbitrary script or HTML code to be executed on the user's browser in the context of the affected site. Cisco has released software updates that address this vulnerability.
CWE: CWE-79, CWE-79
Bug IDs: CSCus21776
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2016-04-12
Published