Cisco Unity Connection XSS Vulnerability (CVE-2015-6390)
Cisco Unity Connection XSS Vulnerability (CVE-2015-6390)
Release date:
Updated on:
Affected Systems:
Cisco Unity Connection 9.1 (1.10)
Description:
CVE (CAN) ID: CVE-2015-6390
Cisco Unity Connection is a fully functional voice messaging platform that uses the Linux Unified Communication operating system.
The management interface of Cisco Unity Connection 9.1 (1.10) has a cross-site scripting vulnerability. Remote attackers can exploit this vulnerability to inject Web scripts or HTML files by Using values constructed in URLs.
<* Source: Cisco
Link: http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151202-pca
*>
Suggestion:
Vendor patch:
Cisco
-----
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.cisco.com/web/CN/products/products_netsol/voices/products/unity_connection/index.html
This article permanently updates the link address: