CVE-2016-6472
published 2016-11-19CVE-2016-6472: A vulnerability in several parameters of the ccmivr page of Cisco Unified Communication Manager (CallManager) could allow an unauthenticated, remote attacker…
PriorityP429medium6.1CVSS 3.0
AVNACLPRNUIRSCCLILAN
EPSS
1.54%
72.4th percentile
A vulnerability in several parameters of the ccmivr page of Cisco Unified Communication Manager (CallManager) could allow an unauthenticated, remote attacker to launch a cross-site scripting (XSS) attack against a user of the web interface on the affected system. More Information: CSCvb37121. Known Affected Releases: 11.5(1.2). Known Fixed Releases: 11.5(1.11950.96) 11.5(1.12900.2) 12.0(0.98000.133) 12.0(0.98000.313) 12.0(0.98000.404).
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
CVSS provenance
nvdv3.06.1MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_cisco4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Unified Communications Manager Web Interface Cross-Site Scripting Vulnerability
vendor_cisco·2016-11-16·CVSS 4.3
CVE-2016-6472 [MEDIUM] CWE-79 Cisco Unified Communications Manager Web Interface Cross-Site Scripting Vulnerability
Cisco Unified Communications Manager Web Interface Cross-Site Scripting Vulnerability
A vulnerability in several parameters of the ccmivr page of Cisco Unified Communication Manager (CallManager) could allow an unauthenticated, remote attacker to launch a cross-site scripting (XSS) attack against a user of the web interface on the affected system.
The vulnerability is due to insufficient input validation of some parameters used by that page. An attacker could exploit this vulnerability by convincing the user of the system to follow an attacker-supplied link. An exploit could allow the attacker to cause arbitrary script or HTML code to be executed on the user's browser within the context of the affected application.
Cisco has not released software updates that address this vulnerability.
Cisco
Cisco Unified Communications Manager Web Interface Cross-Site Scripting Vulnerability
vendor_cisco
CVE-2016-6472 Cisco Unified Communications Manager Web Interface Cross-Site Scripting Vulnerability
CVE-2016-6472: Cisco Unified Communications Manager Web Interface Cross-Site Scripting Vulnerability
A vulnerability in several parameters of the ccmivr page of Cisco Unified Communication Manager (CallManager) could allow an unauthenticated, remote attacker to launch a cross-site scripting (XSS) attack against a user of the web interface on the affected system. The vulnerability is due to insufficient input validation of some parameters used by that page. An attacker could exploit this vulnerability by convincing the user of the system to follow an attacker-supplied link. An exploit could allow the attacker to cause arbitrary script or HTML code to be executed on the user's browser within the context of the affected application. Cisco has not released software updates that address this vu
GHSA
GHSA-7crc-g9gh-wqx2: A vulnerability in several parameters of the ccmivr page of Cisco Unified Communication Manager (CallManager) could allow an unauthenticated, remote a
ghsa_unreviewed·2022-05-17
CVE-2016-6472 [MEDIUM] CWE-79 GHSA-7crc-g9gh-wqx2: A vulnerability in several parameters of the ccmivr page of Cisco Unified Communication Manager (CallManager) could allow an unauthenticated, remote a
A vulnerability in several parameters of the ccmivr page of Cisco Unified Communication Manager (CallManager) could allow an unauthenticated, remote attacker to launch a cross-site scripting (XSS) attack against a user of the web interface on the affected system. More Information: CSCvb37121. Known Affected Releases: 11.5(1.2). Known Fixed Releases: 11.5(1.11950.96) 11.5(1.12900.2) 12.0(0.98000.133) 12.0(0.98000.313) 12.0(0.98000.404).
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/94364http://www.securitytracker.com/id/1037305https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161116-ucmhttp://www.securityfocus.com/bid/94364http://www.securitytracker.com/id/1037305https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161116-ucm
2016-11-19
Published