CVE-2011-1607: Path Traversal
Directory traversal vulnerability in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5)su3, 7.x before 7.1(5b)su3, 8.0 before 8.0(3a)su1, and 8.5 before 8.5(1) allows remote authenticated users to upload files to arbitrary directories via a modified pathname in an upload request, aka Bug ID CSCti81603.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-1607?
CVE-2011-1607 has a CVSS base score indicating a high severity vulnerability.
How do I fix CVE-2011-1607?
To fix CVE-2011-1607, update your Cisco Unified Communications Manager to the latest version as specified in Cisco advisories.
What types of attacks can exploit CVE-2011-1607?
CVE-2011-1607 can be exploited through directory traversal attacks allowing unauthorized file uploads.
Who is affected by CVE-2011-1607?
CVE-2011-1607 affects remote authenticated users of specific versions of Cisco Unified Communications Manager.
What versions of Cisco Unified Communications Manager are impacted by CVE-2011-1607?
CVE-2011-1607 affects Cisco Unified Communications Manager versions 6.x through 8.5 prior to their respective patches.