Cisco Unified Contact Center Express CRS Administration Interface Directory Traversal Vulnerability
BID:35706
Info
Cisco Unified Contact Center Express CRS Administration Interface Directory Traversal Vulnerability
| Bugtraq ID: | 35706 |
| Class: | Input Validation Error |
| CVE: |
CVE-2009-2047 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 15 2009 12:00AM |
| Updated: | Jul 15 2009 07:56PM |
| Credit: | National Australia Bank's Security Assurance team |
| Vulnerable: |
Codeorigin Sysax Multi Server 4.3 Cisco Unified IP Interactive Voice Response 7.x Cisco Unified IP Interactive Voice Response 6.x Cisco Unified IP Interactive Voice Response 5.x Cisco Unified IP Interactive Voice Response 4.x Cisco Unified IP Interactive Voice Response 3.x Cisco Unified Contact Center Express (CCX) 7.x Cisco Unified Contact Center Express (CCX) 6.x Cisco Unified Contact Center Express (CCX) 5.x Cisco IP Queue Manager 3.x Cisco IP Queue Manager Cisco Customer Response Solution (CRS) 7.x Cisco Customer Response Solution (CRS) 6.x Cisco Customer Response Solution (CRS) 5.x Cisco Customer Response Solution (CRS) 4.x Cisco Customer Response Solution (CRS) 3.x Cisco Customer Response Applications 3.x |
| Not Vulnerable: |
Cisco Customer Response Solution (CRS) 7.0(1) SR2 |
Discussion
Cisco Unified Contact Center Express CRS Administration Interface Directory Traversal Vulnerability
Cisco Unified Contact Center Express is prone to a directory-traversal vulnerability.
An attacker can exploit this issue to view, modify, or delete any file on the server through the CRS Administration interface. Successful exploits may lead to other attacks.
This issue is tracked by Cisco BugID CSCsw76644.
Cisco Unified Contact Center Express is prone to a directory-traversal vulnerability.
An attacker can exploit this issue to view, modify, or delete any file on the server through the CRS Administration interface. Successful exploits may lead to other attacks.
This issue is tracked by Cisco BugID CSCsw76644.
Exploit / POC
Cisco Unified Contact Center Express CRS Administration Interface Directory Traversal Vulnerability
An attacker can exploit this issue through a browser.
An attacker can exploit this issue through a browser.
Solution / Fix
Cisco Unified Contact Center Express CRS Administration Interface Directory Traversal Vulnerability
Solution:
The vendor has released an update. Please see the references for details.
Solution:
The vendor has released an update. Please see the references for details.
References
Cisco Unified Contact Center Express CRS Administration Interface Directory Traversal Vulnerability
References:
References: