7.8
CVSSv2

CVE-2011-3315

Published: 27/10/2011 Updated: 27/02/2014
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
VMScore: 785
Vector: AV:N/AC:L/Au:N/C:C/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in Cisco Unified Communications Manager (CUCM) 5.x and 6.x prior to 6.1(5)SU2, 7.x prior to 7.1(5b)SU2, and 8.x prior to 8.0(3), and Cisco Unified Contact Center Express (aka Unified CCX or UCCX) and Cisco Unified IP Interactive Voice Response (Unified IP-IVR) prior to 6.0(1)SR1ES8, 7.0(x) prior to 7.0(2)ES1, 8.0(x) up to and including 8.0(2)SU3, and 8.5(x) prior to 8.5(1)SU2, allows remote malicious users to read arbitrary files via a crafted URL, aka Bug IDs CSCth09343 and CSCts44049.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco unified_ip_interactive_voice_response -

cisco unified_ip_ivr 7.0\\(1\\)

cisco unified_ip_ivr 7.0\\(2\\)

cisco unified_ip_ivr 8.0\\(1\\)

cisco unified_ip_ivr 8.5\\(1\\)

cisco unified_ip_ivr 6.0\\(1\\)

cisco unified_ip_ivr 8.0\\(2\\)

cisco unified communications manager 6.1\\(3b\\)

cisco unified communications manager 6.1\\(2\\)

cisco unified communications manager 6.1\\(2\\)su1a

cisco unified communications manager 6.1\\(1b\\)

cisco unified communications manager 6.0

cisco unified communications manager 6.1\\(5\\)su1

cisco unified communications manager 7.1\\(3a\\)su1

cisco unified communications manager 7.1\\(3b\\)

cisco unified communications manager 7.1\\(3a\\)

cisco unified communications manager 7.1\\(3\\)

cisco unified communications manager 7.0\\(2a\\)

cisco unified communications manager 7.1\\(2a\\)

cisco unified communications manager 7.1\\(2a\\)su1

cisco unified communications manager 7.1\\(2b\\)

cisco unified communications manager 5.1\\(1\\)

cisco unified communications manager 5.1\\(1b\\)

cisco unified communications manager 5.1\\(1c\\)

cisco unified communications manager 5.1\\(2\\)

cisco unified communications manager 6.1\\(3b\\)su1

cisco unified communications manager 6.1\\(4\\)

cisco unified communications manager 6.1\\(4a\\)su2

cisco unified communications manager 6.1\\(2\\)su1

cisco unified communications manager 7.1\\(3b\\)su1

cisco unified communications manager 7.1\\(5\\)su1a

cisco unified communications manager 7.0\\(1\\)su1

cisco unified communications manager 7.0\\(2a\\)su2

cisco unified communications manager 7.1\\(5b\\)su1

cisco unified communications manager 8.0

cisco unified communications manager 8.0\\(2b\\)

cisco unified communications manager 5.1

cisco unified communications manager 5.1\\(2a\\)

cisco unified communications manager 5.1\\(3\\)

cisco unified communications manager 6.1\\(5\\)

cisco unified communications manager 6.1\\(1a\\)

cisco unified communications manager 6.1\\(4\\)su1

cisco unified communications manager 7.1\\(5\\)su1

cisco unified communications manager 7.1\\(5b\\)

cisco unified communications manager 7.1\\(5a\\)

cisco unified communications manager 7.0\\(2\\)

cisco unified communications manager 8.0\\(2c\\)

cisco unified communications manager 8.0\\(2c\\)su1

cisco unified communications manager 7.1\\(3b\\)su2

cisco unified communications manager 8.0\\(1\\)

cisco unified communications manager 8.0\\(2\\)

cisco unified communications manager 5.1\\(3c\\)

cisco unified communications manager 5.1\\(3d\\)

cisco unified communications manager 5.1\\(3e\\)

cisco unified communications manager 5.1.2

cisco unified communications manager 6.1\\(4a\\)

cisco unified communications manager 6.1\\(3a\\)

cisco unified communications manager 6.1\\(3\\)

cisco unified communications manager 6.1\\(1\\)

cisco unified communications manager 7.1\\(5\\)

cisco unified communications manager 7.1\\(3a\\)su1a

cisco unified communications manager 7.0\\(2a\\)su1

cisco unified communications manager 7.0\\(1\\)su1a

cisco unified communications manager 7.1\\(2b\\)su1

cisco unified communications manager 7.1\\(5b\\)su1a

cisco unified communications manager 8.0\\(2a\\)

cisco unified communications manager 5.0

cisco unified communications manager 5.1\\(2b\\)

cisco unified communications manager 5.1\\(3a\\)

Exploits

source: wwwsecurityfocuscom/bid/50372/info Multiple Cisco products are prone to a directory-traversal vulnerability Exploiting this issue will allow an attacker to read arbitrary files from locations outside of the application's current directory This could help the attacker launch further attacks This issue is tracked by Cisco BugID ...