4
CVSSv2

CVE-2015-0758

Published: 30/05/2015 Updated: 04/01/2017
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

The web-based user interface in Cisco Unified MeetingPlace 8.6(1.9) allows remote malicious users to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, aka Bug ID CSCus97452.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco unified meetingplace 8.6\\(1.9\\)

Vendor Advisories

A vulnerability in the web-based user interface of Cisco Unified MeetingPlace could allow an authenticated, remote attacker to gain read access to select information stored on the affected system The vulnerability is due to improper handling of XML External Entities (XXEs) when parsing an XML file An attacker could exploit this vulnerability by ...