Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-15259

Опубликовано: 02 окт. 2019
Источник: nvd
CVSS3: 6.1
CVSS3: 6.1
CVSS2: 4.3
EPSS Низкий

Описание

A vulnerability in Cisco Unified Contact Center Express (UCCX) Software could allow an unauthenticated, remote attacker to conduct an HTTP response splitting attack. The vulnerability is due to insufficient input validation of some parameters that are passed to the web server of the affected system. An attacker could exploit this vulnerability by convincing a user to follow a malicious link or by intercepting a user request on an affected device. A successful exploit could allow the attacker to perform cross-site scripting attacks, web cache poisoning, access sensitive browser-based information, and similar exploits.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:cisco:unified_contact_center_express:*:*:*:*:*:*:*:*
Версия до 11.6\(2\) (исключая)
cpe:2.3:a:cisco:unified_contact_center_express:12.0\(1\):*:*:*:*:*:*:*

EPSS

Процентиль: 43%
0.00208
Низкий

6.1 Medium

CVSS3

6.1 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-113
CWE-74

Связанные уязвимости

github
больше 3 лет назад

A vulnerability in Cisco Unified Contact Center Express (UCCX) Software could allow an unauthenticated, remote attacker to conduct an HTTP response splitting attack. The vulnerability is due to insufficient input validation of some parameters that are passed to the web server of the affected system. An attacker could exploit this vulnerability by convincing a user to follow a malicious link or by intercepting a user request on an affected device. A successful exploit could allow the attacker to perform cross-site scripting attacks, web cache poisoning, access sensitive browser-based information, and similar exploits.

CVSS3: 6.1
fstec
больше 6 лет назад

Уязвимость программного средства автоматизации работы операторов Cisco Unified Contact Center Express, существующая из-за недостаточной проверки входных данных, позволяющая нарушителю выполнить межсайтовые скриптовые атаки или получить доступ к конфиденциальной информации

EPSS

Процентиль: 43%
0.00208
Низкий

6.1 Medium

CVSS3

6.1 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-113
CWE-74