This site is deprecated. Please
CLICK HERE for latest updates
Short Name |
HTTP:CISCO:CUCM-DIR-TRAV
|
Severity |
Minor
|
Recommended |
No
|
Recommended Action |
Drop
|
Category |
HTTP
|
Keywords |
Cisco Unified Communications Manager IVRGetAudioFile.do Directory Traversal
|
Release Date |
2011/11/16
|
Update Number |
2031
|
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+
|
HTTP: Cisco Unified Communications Manager IVRGetAudioFile.do Directory Traversal
This signature detects attempts to exploit directory traversal vulnerability in the IVRGetAudioFile.do script of Cisco Unified Communications Manager (CUCM). A successful attack can result in arbitrary code execution and/or loss of sensitive information.
Extended Description
Multiple Cisco products are prone to a directory-traversal vulnerability.
Exploiting this issue will allow an attacker to read arbitrary files from locations outside of the application's current directory. This could help the attacker launch further attacks.
This issue is tracked by Cisco BugID CSCts44049 and CSCth09343.
The following products are affected:
Cisco Unified IP Interactive Voice Response
Cisco Unified Contact Center Express
Cisco Unified Communications Manager
Affected Products
- Cisco unified_communications_manager 6.1
- Cisco unified_communications_manager 6.1(1)
- Cisco unified_communications_manager 6.1(1A)
- Cisco unified_communications_manager 6.1(1B)
- Cisco unified_communications_manager 6.1(2)
- Cisco unified_communications_manager 6.1 (2)Su1
- Cisco unified_communications_manager 6.1(2)Su1a
- Cisco unified_communications_manager 6.1(3)
- Cisco unified_communications_manager 6.1(3A)
- Cisco unified_communications_manager 6.1(3B)
- Cisco unified_communications_manager 6.1 (3B)Su1
- Cisco unified_communications_manager 6.1(4)
- Cisco unified_communications_manager 6.1(4A)
- Cisco unified_communications_manager 6.1(4A)Su2
- Cisco unified_communications_manager 6.1(4)Su1
- Cisco unified_communications_manager 6.1(5)
- Cisco unified_communications_manager 6.1(5)SU1
- Cisco unified_communications_manager 7.0
- Cisco unified_communications_manager 7.0(1)Su1
- Cisco unified_communications_manager 7.0(1)Su1a
- Cisco unified_communications_manager 7.0(2)
- Cisco unified_communications_manager 7.0(2A)
- Cisco unified_communications_manager 7.0(2A)Su1
- Cisco unified_communications_manager 7.0(2A)Su2
- Cisco unified_communications_manager 7.0(2a)SU3
- Cisco unified_communications_manager 7.0(2a)SU3
- Cisco unified_communications_manager 7.0(3G)
- Cisco unified_communications_manager 7.1
- Cisco unified_communications_manager 7.1(2)
- Cisco unified_communications_manager 7.1(2A)
- Cisco unified_communications_manager 7.1(2A)Su1
- Cisco unified_communications_manager 7.1(2B)
- Cisco unified_communications_manager 7.1(2B)Su1
- Cisco unified_communications_manager 7.1(3)
- Cisco unified_communications_manager 7.1(3A)
- Cisco unified_communications_manager 7.1(3A)Su1
- Cisco unified_communications_manager 7.1(3A)Su1a
- Cisco unified_communications_manager 7.1(3B)
- Cisco unified_communications_manager 7.1(3B)Su1
- Cisco unified_communications_manager 7.1(3B)Su2
- Cisco unified_communications_manager 7.1(5)
- Cisco unified_communications_manager 7.1(5A)
- Cisco unified_communications_manager 7.1(5B)
- Cisco unified_communications_manager 7.1(5)Su1
- Cisco unified_communications_manager 7.1(5)Su1a
- Cisco unified_contact_center_express_(ccx) 6.0(1)SR1
- Cisco unified_contact_center_express_(ccx) 6.X
- Cisco unified_contact_center_express_(ccx) 7.0(1)SR2
- Cisco unified_contact_center_express_(ccx) 7.0(1)SR4
- Cisco unified_contact_center_express_(ccx) 7.0(2)
- Cisco unified_contact_center_express_(ccx) 7.X
- Cisco unified_contact_center_express_(ccx) 8.0
- Cisco unified_ip_interactive_voice_response 6.X
- Cisco unified_ip_interactive_voice_response 7.X
- Cisco unified_ip_interactive_voice_response 8.0
- Cisco unified_ip_interactive_voice_response 8.5
References