First published: Thu Jul 10 2014(Updated: )
Cross-site scripting (XSS) vulnerability in viewfilecontents.do in the Dialed Number Analyzer (DNA) component in Cisco Unified Communications Manager allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCup76308.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Unified Communications Manager | ||
Cisco Unified Communications Manager | =10.0\(1\)_base |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2014-3315 is classified as medium due to the potential for cross-site scripting attacks.
To fix CVE-2014-3315, upgrade Cisco Unified Communications Manager to a version that addresses this vulnerability.
CVE-2014-3315 allows remote attackers to perform cross-site scripting (XSS) attacks by injecting arbitrary web scripts or HTML.
CVE-2014-3315 affects multiple versions of Cisco Unified Communications Manager, including version 10.0(1)_base.
As of the latest information, there have been no confirmed reports of exploitation in the wild for CVE-2014-3315.