CVE-2013-1225
Severity CVSS v4.0:
Pending analysis
Type:
CWE-264
Permissions, Privileges, and Access Control
Publication date:
09/05/2013
Last modified:
09/05/2013
Description
Cisco Unified Customer Voice Portal (CVP) Software before 9.0.1 ES 11 allows remote attackers to read arbitrary files via a Resource Manager (1) HTTP or (2) HTTPS request containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, aka Bug ID CSCub38366.
Impact
Base Score 2.0
7.80
Severity 2.0
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:cisco:unified_customer_voice_portal:*:*:*:*:*:*:*:* | 9.0\(1\) (including) | |
cpe:2.3:a:cisco:unified_customer_voice_portal:3.0:sr1:*:*:*:*:*:* | ||
cpe:2.3:a:cisco:unified_customer_voice_portal:3.0:sr2:*:*:*:*:*:* | ||
cpe:2.3:a:cisco:unified_customer_voice_portal:3.6\(10\):es01:*:*:*:*:*:* | ||
cpe:2.3:a:cisco:unified_customer_voice_portal:4.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:cisco:unified_customer_voice_portal:4.0\(2\):*:*:*:*:*:*:* | ||
cpe:2.3:a:cisco:unified_customer_voice_portal:4.0\(2\):sr1:*:*:*:*:*:* | ||
cpe:2.3:a:cisco:unified_customer_voice_portal:4.1:*:*:*:*:*:*:* | ||
cpe:2.3:a:cisco:unified_customer_voice_portal:7.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:cisco:unified_customer_voice_portal:7.0\(2\):*:*:*:*:*:*:* | ||
cpe:2.3:a:cisco:unified_customer_voice_portal:8.0\(1\):*:*:*:*:*:*:* | ||
cpe:2.3:a:cisco:unified_customer_voice_portal:8.5\(1\):*:*:*:*:*:*:* | ||
cpe:2.3:a:cisco:unified_customer_voice_portal:9.0:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page