4.3
CVSSv2

CVE-2014-3315

Published: 10/07/2014 Updated: 29/08/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in viewfilecontents.do in the Dialed Number Analyzer (DNA) component in Cisco Unified Communications Manager allows remote malicious users to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCup76308.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco unified communications manager 10.0\\(1\\)_base

cisco unified communications manager

Vendor Advisories

A vulnerability in the Dialed Number Analyzer (DNA) of Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to perform a cross-site scripting (XSS) attack against the user of a web interface The vulnerability is due to insufficient input validation of a parameter in the viewfilecontentsdo page An attacker could e ...