Show filters
27 Total Results
Displaying 11-20 of 27
Sort by:
Attacker Value
Unknown

CVE-2017-3845

Disclosure Date: February 22, 2017 (last updated November 26, 2024)
A vulnerability in the web-based management interface of Cisco Prime Collaboration Assurance could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. Affected Products: Cisco Prime Collaboration Assurance software versions 11.0, 11.1, and 11.5 are vulnerable. Cisco Prime Collaboration Assurance software versions prior to 11.0 are not vulnerable. More Information: CSCvc77783. Known Affected Releases: 11.5(0).
0
Attacker Value
Unknown

CVE-2016-9200

Disclosure Date: December 14, 2016 (last updated November 25, 2024)
A vulnerability in the web framework code of Cisco Prime Collaboration Assurance could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the user of the web interface. More Information: CSCut43268. Known Affected Releases: 10.5(1) 10.6.
0
Attacker Value
Unknown

CVE-2016-1392

Disclosure Date: May 05, 2016 (last updated November 25, 2024)
Open redirect vulnerability in Cisco Prime Collaboration Assurance Software 10.5 through 11.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors, aka Bug ID CSCuu34121.
0
Attacker Value
Unknown

CVE-2015-6389

Disclosure Date: December 13, 2015 (last updated October 05, 2023)
Cisco Prime Collaboration Assurance before 11.0 has a hardcoded cmuser account, which allows remote attackers to obtain access by establishing an SSH session and leveraging knowledge of this account's password, aka Bug ID CSCus62707.
0
Attacker Value
Unknown

CVE-2015-6330

Disclosure Date: November 18, 2015 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in Cisco Prime Collaboration Assurance 10.5(1) and 10.6 allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCus62712.
0
Attacker Value
Unknown

CVE-2015-6328

Disclosure Date: October 13, 2015 (last updated October 05, 2023)
The web framework in Cisco Prime Collaboration Assurance (PCA) 10.5(1) allows remote authenticated users to bypass intended access restrictions and read arbitrary files via a crafted URL, aka Bug ID CSCus88380.
0
Attacker Value
Unknown

CVE-2015-6331

Disclosure Date: October 12, 2015 (last updated October 05, 2023)
SQL injection vulnerability in the web framework in Cisco Prime Collaboration Assurance 10.5(1) allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCus39887.
0
Attacker Value
Unknown

CVE-2015-4305

Disclosure Date: September 20, 2015 (last updated October 05, 2023)
The web framework in Cisco Prime Collaboration Assurance before 10.5.1.53684-1 allows remote authenticated users to bypass intended system-database read restrictions, and discover credentials or SNMP communities for arbitrary tenant domains, via a crafted URL, aka Bug ID CSCus62656.
0
Attacker Value
Unknown

CVE-2015-4306

Disclosure Date: September 20, 2015 (last updated October 05, 2023)
The web framework in Cisco Prime Collaboration Assurance before 10.5.1.53684-1 allows remote authenticated users to bypass intended login-session read restrictions, and impersonate administrators of arbitrary tenant domains, by discovering a session identifier and constructing a crafted URL, aka Bug IDs CSCus88343 and CSCus88334.
0
Attacker Value
Unknown

CVE-2015-4304

Disclosure Date: September 20, 2015 (last updated October 05, 2023)
The web framework in Cisco Prime Collaboration Assurance before 10.5.1.53684-1 allows remote authenticated users to bypass intended access restrictions, and create administrative accounts or read data from arbitrary tenant domains, via a crafted URL, aka Bug IDs CSCus62671 and CSCus62652.
0