6.8
CVSSv2

CVE-2014-2194

Published: 20/05/2014 Updated: 20/05/2014
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

system/egain/chat/entrypoint in Cisco Unified Web and E-mail Interaction Manager 9.0(2) allows remote malicious users to have an unspecified impact by injecting a spoofed XML external entity.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco unified web and e-mail interaction manager 9.0\\(2\\)

Vendor Advisories

A vulnerability in the /system/egain/chat/entrypoint script of Cisco Unified Web and E-mail Interaction Manager could allow an unauthenticated, remote attacker to inject malicious XML entities The vulnerability is due to inadequate input validation An attacker could exploit this vulnerability by spoofing an XML external entity Cisco has confir ...