CVE-2016-6371
published 2016-09-12CVE-2016-6371: Directory traversal vulnerability in the web interface in Cisco Hosted Collaboration Mediation Fulfillment (HCM-F) 10.6(3) and earlier allows remote attackers…
PriorityP347high7.5CVSS 3.0
AVNACLPRNUINSUCNIHAN
EPSS
4.78%
91.0th percentile
Directory traversal vulnerability in the web interface in Cisco Hosted Collaboration Mediation Fulfillment (HCM-F) 10.6(3) and earlier allows remote attackers to write to arbitrary files via a crafted URL, aka Bug ID CSCuz64717.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | hosted_collaboration_mediation_fulfillment | — | — |
| cisco | hosted_collaboration_mediation_fulfillment | — | — |
| cisco | hosted_collaboration_mediation_fulfillment | — | — |
| cisco | hosted_collaboration_mediation_fulfillment_directory | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
vendor_cisco5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Hosted Collaboration Mediation Fulfillment Directory Traversal File System Vulnerability
vendor_cisco·2016-08-31·CVSS 5.0
CVE-2016-6371 [MEDIUM] CWE-22 Cisco Hosted Collaboration Mediation Fulfillment Directory Traversal File System Vulnerability
Cisco Hosted Collaboration Mediation Fulfillment Directory Traversal File System Vulnerability
A vulnerability in the web interface of Cisco Hosted Collaboration Mediation Fulfillment application could allow an unauthenticated, remote attacker to write arbitrary files to any file system location that the application server has permissions to access.
The vulnerability is due to lack of proper input validation of the HTTP URL format. An attacker could exploit this vulnerability by sending a crafted HTTP to the affected application. An exploit could allow the attacker to write out an arbitrary file. The format of the data written to these file is restricted.
Cisco has not released software updates that address this vulnerability. Workarounds that address this vulnerability are not availabl
Cisco
Cisco Hosted Collaboration Mediation Fulfillment Directory Traversal File System Vulnerability
vendor_cisco
CVE-2016-6371 Cisco Hosted Collaboration Mediation Fulfillment Directory Traversal File System Vulnerability
CVE-2016-6371: Cisco Hosted Collaboration Mediation Fulfillment Directory Traversal File System Vulnerability
A vulnerability in the web interface of Cisco Hosted Collaboration Mediation Fulfillment application could allow an unauthenticated, remote attacker to write arbitrary files to any file system location that the application server has permissions to access. The vulnerability is due to lack of proper input validation of the HTTP URL format. An attacker could exploit this vulnerability by sending a crafted HTTP to the affected application. An exploit could allow the attacker to write out an arbitrary file. The format of the data written to these file is restricted. Cisco has not released software updates that address this vulnerability.
CWE: CWE-22, CWE-22
Bug IDs: CSCuz64717
GHSA
GHSA-5v82-px86-qrw9: Directory traversal vulnerability in the web interface in Cisco Hosted Collaboration Mediation Fulfillment (HCM-F) 10
ghsa_unreviewed·2022-05-17
CVE-2016-6371 [HIGH] CWE-22 GHSA-5v82-px86-qrw9: Directory traversal vulnerability in the web interface in Cisco Hosted Collaboration Mediation Fulfillment (HCM-F) 10
Directory traversal vulnerability in the web interface in Cisco Hosted Collaboration Mediation Fulfillment (HCM-F) 10.6(3) and earlier allows remote attackers to write to arbitrary files via a crafted URL, aka Bug ID CSCuz64717.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160831-hcmfhttp://www.securityfocus.com/bid/92705http://www.securitytracker.com/id/1036719http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160831-hcmfhttp://www.securityfocus.com/bid/92705http://www.securitytracker.com/id/1036719
2016-09-12
Published