CVE-2011-1607 Information

Description

Directory traversal vulnerability in Cisco Unified Communications Manager (aka CUCM formerly CallManager) 6.x before 6.1(5)su3 7.x before 7.1(5b)su3 8.0 before 8.0(3a)su1 and 8.5 before 8.5(1) allows remote authenticated users to upload files to arbitrary directories via a modified pathname in an upload request aka Bug ID CSCti81603.

Reference

http://archives.neohapsis.com/archives/fulldisclosure/2011-05/0051.html http://secunia.com/advisories/44331 http://www.cisco.com/en/US/products/products_security_advisory09186a0080b79904.shtml http://www.securityfocus.com/bid/47608 http://www.securitytracker.com/id?1025449 http://www.vupen.com/english/advisories/2011/1122 https://exchange.xforce.ibmcloud.com/vulnerabilities/67127

Share on: