7.8
CVSSv2

CVE-2013-1225

Published: 09/05/2013 Updated: 09/05/2013
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
VMScore: 694
Vector: AV:N/AC:L/Au:N/C:C/I:N/A:N

Vulnerability Summary

Cisco Unified Customer Voice Portal (CVP) Software prior to 9.0.1 ES 11 allows remote malicious users to read arbitrary files via a Resource Manager (1) HTTP or (2) HTTPS request containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, aka Bug ID CSCub38366.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco unified customer voice portal 8.5\\(1\\)

cisco unified customer voice portal 7.0\\(2\\)

cisco unified customer voice portal 4.0\\(2\\)

cisco unified customer voice portal 4.0

cisco unified customer voice portal 7.0

cisco unified customer voice portal 3.0

cisco unified customer voice portal 3.6\\(10\\)

cisco unified customer voice portal 4.1

cisco unified customer voice portal 9.0

cisco unified customer voice portal 8.0\\(1\\)

cisco unified customer voice portal

Vendor Advisories

Cisco Unified Customer Voice Portal Software (Unified CVP) contains multiple vulnerabilities Various components of Cisco Unified CVP are affected; see the "Details" section for more information on the vulnerabilities These vulnerabilities can be exploited independently; however, more than one vulnerability could be exploited on the same device ...