|
267271
|
4.3 |
MEDIUM
Network
|
zyxel
|
gs1900-10hp_firmware
|
Cisco Unified Communications Manager 11.5(0.98000.480) allows remote authenticated users to obtain sensitive database table-name and entity-name information via a direct request to an unspecified URL…
|
CWE-200
Information Exposure
|
CVE-2016-1317
|
2024-11-21 11:46 |
2016-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267272
|
5.3 |
MEDIUM
Network
|
cisco
|
telepresence_video_communication_server_software
|
Cisco TelePresence Video Communication Server (VCS) X8.1 through X8.7, as used in conjunction with Jabber Guest, allows remote attackers to obtain sensitive call-statistics information via a direct r…
|
CWE-200
Information Exposure
|
CVE-2016-1316
|
2024-11-21 11:46 |
2016-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267273
|
6.1 |
MEDIUM
Network
|
cisco
|
webex_meetings_server
|
Multiple cross-site scripting (XSS) vulnerabilities in Cisco WebEx Meetings Server 2.5.1.5 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug ID CSCuy01…
|
CWE-79
Cross-site Scripting
|
CVE-2016-1309
|
2024-11-21 11:46 |
2016-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267274
|
6.5 |
MEDIUM
Network
|
samsung
|
x14j_firmware
|
SQL injection vulnerability in Cisco Unified Communications Manager 10.5(2.13900.9) allows remote authenticated users to execute arbitrary SQL commands via a crafted URL, aka Bug ID CSCux99227.
|
CWE-89
SQL Injection
|
CVE-2016-1308
|
2024-11-21 11:46 |
2016-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267275
|
5.4 |
MEDIUM
Network
|
zyxel zzinc
|
gs1900-10hp_firmware keymouse_firmware
|
The Openfire server in Cisco Finesse Desktop 10.5(1) and 11.0(1) and Unified Contact Center Express 10.6(1) has a hardcoded account, which makes it easier for remote attackers to obtain access via an…
|
CWE-287 CWE-255
Improper Authentication Credentials Management
|
CVE-2016-1307
|
2024-11-21 11:46 |
2016-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267276
|
6.1 |
MEDIUM
Network
|
cisco
|
application_policy_infrastructure_controller_enterprise_module
|
Cross-site scripting (XSS) vulnerability in Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM) 1.1 allows remote attackers to inject arbitrary web script or HTML via vecto…
|
CWE-79
Cross-site Scripting
|
CVE-2016-1305
|
2024-11-21 11:46 |
2016-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267277
|
8.8 |
HIGH
Network
|
samsung sun zyxel zzinc cisco
|
x14j_firmware opensolaris gs1900-10hp_firmware keymouse_firmware nx-os
|
Cisco Application Policy Infrastructure Controller (APIC) devices with software before 1.0(3h) and 1.1 before 1.1(1j) and Nexus 9000 ACI Mode switches with software before 11.0(3h) and 11.1 before 11…
|
CWE-284
Improper Access Control
|
CVE-2016-1302
|
2024-11-21 11:46 |
2016-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267278
|
8.8 |
HIGH
Network
|
cisco
|
asa_cx_context-aware_security_software prime_security_manager
|
The RBAC implementation in Cisco ASA-CX Content-Aware Security software before 9.3.1.1(112) and Cisco Prime Security Manager (PRSM) software before 9.3.1.1(112) allows remote authenticated users to c…
|
CWE-284
Improper Access Control
|
CVE-2016-1301
|
2024-11-21 11:46 |
2016-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267279
|
6.1 |
MEDIUM
Network
|
cisco
|
jabber_guest
|
Cross-site scripting (XSS) vulnerability in the management interface in Cisco Jabber Guest Server 10.6(8) allows remote attackers to inject arbitrary web script or HTML via the host tag parameter, ak…
|
CWE-79
Cross-site Scripting
|
CVE-2016-1311
|
2024-11-21 11:46 |
2016-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267280
|
6.1 |
MEDIUM
Network
|
sun
|
opensolaris
|
Cross-site scripting (XSS) vulnerability in Cisco Unity Connection 11.5(0.199) allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCuy09033.
|
CWE-79
Cross-site Scripting
|
CVE-2016-1310
|
2024-11-21 11:46 |
2016-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|