Lucene search

K
cveCiscoCVE-2015-0762
HistoryJun 04, 2015 - 10:59 a.m.

CVE-2015-0762

2015-06-0410:59:02
CWE-79
cisco
web.nvd.nist.gov
28
cve-2015-0762
xss
cisco
unified meetingplace
vulnerability
nvd
security
bug cscuu51400

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.8

Confidence

High

EPSS

0.001

Percentile

43.4%

Cross-site scripting (XSS) vulnerability in the management interface in Cisco Unified MeetingPlace 8.6(1.2) and 8.6(1.9) for Microsoft Outlook allows remote attackers to inject arbitrary web script or HTML via a crafted value in a URL, aka Bug ID CSCuu51400.

Affected configurations

Nvd
Node
ciscounified_meetingplaceMatch8.6\(1.2\)
OR
ciscounified_meetingplaceMatch8.6\(1.9\)
VendorProductVersionCPE
ciscounified_meetingplace8.6(1.2)cpe:2.3:a:cisco:unified_meetingplace:8.6\(1.2\):*:*:*:*:*:*:*
ciscounified_meetingplace8.6(1.9)cpe:2.3:a:cisco:unified_meetingplace:8.6\(1.9\):*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.8

Confidence

High

EPSS

0.001

Percentile

43.4%

Related for CVE-2015-0762