Cisco Unified Contact Center Express (CCX) Arbitrary Script Injection Vulnerability
BID:35705
Info
Cisco Unified Contact Center Express (CCX) Arbitrary Script Injection Vulnerability
| Bugtraq ID: | 35705 |
| Class: | Input Validation Error |
| CVE: |
CVE-2009-2048 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 15 2009 12:00AM |
| Updated: | Jul 15 2009 06:26PM |
| Credit: | National Australia Bank's Security Assurance team |
| Vulnerable: |
Cisco Unified IP Interactive Voice Response 7.x Cisco Unified IP Interactive Voice Response 6.x Cisco Unified IP Interactive Voice Response 5.x Cisco Unified IP Interactive Voice Response 4.x Cisco Unified IP Interactive Voice Response 3.x Cisco Unified IP Contact Center Express 7.x Cisco Unified IP Contact Center Express 6.x Cisco Unified IP Contact Center Express 5.x Cisco Unified IP Contact Center Express 3.x Cisco Unified Contact Center Express (CCX) 7.x Cisco Unified Contact Center Express (CCX) 6.x Cisco Unified Contact Center Express (CCX) 5.x Cisco Unified Contact Center Express (CCX) 4.x Cisco Unified Contact Center Express 0 Cisco IP Queue Manager 3.x Cisco IP Queue Manager Cisco IP Contact Center Express Cisco Customer Response Solution (CRS) 7.x Cisco Customer Response Solution (CRS) 6.x Cisco Customer Response Solution (CRS) 5.x Cisco Customer Response Solution (CRS) 4.x Cisco Customer Response Solution (CRS) 3.x Cisco Customer Response Applications 3.x |
| Not Vulnerable: |
Cisco Customer Response Solution (CRS) 7.0(1) SR2 |
Discussion
Cisco Unified Contact Center Express (CCX) Arbitrary Script Injection Vulnerability
Cisco Unified Contact Center Express (CCX) is prone to a vulnerability that allows attackers to execute arbitrary script code because it fails to properly sanitize user-supplied input.
An attacker can exploit this issue to execute arbitrary script code in the context of the user running the application, which may aid in further attacks.
This issue is documented by Cisco Bug ID CSCsw76649.
Cisco Unified Contact Center Express (CCX) is prone to a vulnerability that allows attackers to execute arbitrary script code because it fails to properly sanitize user-supplied input.
An attacker can exploit this issue to execute arbitrary script code in the context of the user running the application, which may aid in further attacks.
This issue is documented by Cisco Bug ID CSCsw76649.
Exploit / POC
Cisco Unified Contact Center Express (CCX) Arbitrary Script Injection Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Cisco Unified Contact Center Express (CCX) Arbitrary Script Injection Vulnerability
Solution:
The vendor has released an advisory and fixes. Please see the references for more information.
Solution:
The vendor has released an advisory and fixes. Please see the references for more information.
References
Cisco Unified Contact Center Express (CCX) Arbitrary Script Injection Vulnerability
References:
References: