Show filters
26 Total Results
Displaying 11-20 of 26
Sort by:
Attacker Value
Unknown

CVE-2017-12227

Disclosure Date: September 07, 2017 (last updated November 26, 2024)
A vulnerability in the SQL database interface for Cisco Emergency Responder could allow an authenticated, remote attacker to conduct a blind SQL injection attack. The vulnerability is due to a failure to validate user-supplied input used in SQL queries that bypass protection filters. An attacker could exploit this vulnerability by sending crafted URLs that include SQL statements. An exploit could allow the attacker to view or modify entries in some database tables, affecting the integrity of the data. Cisco Bug IDs: CSCvb58973.
0
Attacker Value
Unknown

CVE-2016-6468

Disclosure Date: December 14, 2016 (last updated November 25, 2024)
A vulnerability in the web-based management interface of Cisco Emergency Responder could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. More Information: CSCvb06663. Known Affected Releases: 11.5(1.10000.4). Known Fixed Releases: 12.0(0.98000.14).
0
Attacker Value
Unknown

CVE-2016-9208

Disclosure Date: December 14, 2016 (last updated November 25, 2024)
A vulnerability in the File Management Utility, the Download File form, and the Serviceability application of Cisco Emergency Responder could allow an authenticated, remote attacker to access files in arbitrary locations on the file system of an affected device. More Information: CSCva98951 CSCva98954 CSCvb57494. Known Affected Releases: 11.5(2.10000.5). Known Fixed Releases: 12.0(0.98000.14) 12.0(0.98000.16).
0
Attacker Value
Unknown

CVE-2015-6405

Disclosure Date: December 13, 2015 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in Cisco Emergency Responder 10.5(1) and 10.5(1a) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuv26501.
0
Attacker Value
Unknown

CVE-2015-6407

Disclosure Date: December 13, 2015 (last updated October 05, 2023)
Cisco Emergency Responder 10.5(3.10000.9) allows remote attackers to upload files to arbitrary locations via a crafted parameter, aka Bug ID CSCuv25501.
0
Attacker Value
Unknown

CVE-2015-6400

Disclosure Date: December 13, 2015 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Cisco Emergency Responder 10.5(1a) allow remote attackers to inject arbitrary web script or HTML via unspecified fields, aka Bug ID CSCuv25547.
0
Attacker Value
Unknown

CVE-2015-6406

Disclosure Date: December 13, 2015 (last updated October 05, 2023)
Directory traversal vulnerability in the Tools menu in Cisco Emergency Responder 10.5(1.10000.5) allows remote authenticated users to write to arbitrary files via a crafted filename, aka Bug ID CSCuv21781.
0
Attacker Value
Unknown

CVE-2014-2114

Disclosure Date: April 04, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in UserServlet in Cisco Emergency Responder (ER) 8.6 and earlier allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCun24384.
0
Attacker Value
Unknown

CVE-2014-2116

Disclosure Date: April 04, 2014 (last updated October 05, 2023)
Cisco Emergency Responder (ER) 8.6 and earlier allows remote attackers to inject web pages and modify dynamic content via unspecified parameters, aka Bug ID CSCun37882.
0
Attacker Value
Unknown

CVE-2014-2115

Disclosure Date: April 04, 2014 (last updated October 05, 2023)
Multiple cross-site request forgery (CSRF) vulnerabilities in CERUserServlet pages in Cisco Emergency Responder (ER) 8.6 and earlier allow remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCun24250.
0