4
CVSSv2

CVE-2015-6407

Published: 13/12/2015 Updated: 07/12/2016
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N

Vulnerability Summary

Cisco Emergency Responder 10.5(3.10000.9) allows remote malicious users to upload files to arbitrary locations via a crafted parameter, aka Bug ID CSCuv25501.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco emergency responder 10.5\\(3.10000.9\\)

Vendor Advisories

A vulnerability in the web framework of Cisco Emergency Responder (CER) could allow an unauthenticated, remote attacker to upload arbitrary files to a restricted location on the filesystem The vulnerability is due to insufficient parameter validation An attacker could exploit this vulnerability by sending a crafted request to the server An expl ...