Show filters
340 Total Results
Displaying 281-290 of 340
Sort by:
Attacker Value
Unknown

CVE-2015-4305

Disclosure Date: September 20, 2015 (last updated October 05, 2023)
The web framework in Cisco Prime Collaboration Assurance before 10.5.1.53684-1 allows remote authenticated users to bypass intended system-database read restrictions, and discover credentials or SNMP communities for arbitrary tenant domains, via a crafted URL, aka Bug ID CSCus62656.
0
Attacker Value
Unknown

CVE-2015-4306

Disclosure Date: September 20, 2015 (last updated October 05, 2023)
The web framework in Cisco Prime Collaboration Assurance before 10.5.1.53684-1 allows remote authenticated users to bypass intended login-session read restrictions, and impersonate administrators of arbitrary tenant domains, by discovering a session identifier and constructing a crafted URL, aka Bug IDs CSCus88343 and CSCus88334.
0
Attacker Value
Unknown

CVE-2015-4304

Disclosure Date: September 20, 2015 (last updated October 05, 2023)
The web framework in Cisco Prime Collaboration Assurance before 10.5.1.53684-1 allows remote authenticated users to bypass intended access restrictions, and create administrative accounts or read data from arbitrary tenant domains, via a crafted URL, aka Bug IDs CSCus62671 and CSCus62652.
0
Attacker Value
Unknown

CVE-2015-6296

Disclosure Date: September 18, 2015 (last updated October 05, 2023)
Cisco Prime Network Registrar (CPNR) 8.1(3.3), 8.2(3), and 8.3(2) has a default account, which allows local users to obtain root access by leveraging knowledge of the credentials, aka Bug ID CSCuw21825.
0
Attacker Value
Unknown

CVE-2015-6262

Disclosure Date: August 25, 2015 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in Cisco Prime Infrastructure 1.2(0.103) and 2.0(0.0) allows remote attackers to hijack the authentication of arbitrary users, aka Bug IDs CSCum49054 and CSCum49059.
0
Attacker Value
Unknown

CVE-2015-4331

Disclosure Date: August 22, 2015 (last updated October 05, 2023)
Cisco Prime Infrastructure (PI) 1.4(0.45) and earlier, when AAA authentication is used, allows remote authenticated users to bypass intended access restrictions via a username with a modified composition of lowercase and uppercase characters, aka Bug ID CSum59958.
0
Attacker Value
Unknown

CVE-2015-4292

Disclosure Date: August 01, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the management interface in Cisco Prime Central for Hosted Collaboration Solution (PC4HCS) 10.6(2) allows remote attackers to inject arbitrary web script or HTML via an unspecified value, aka Bug ID CSCuv45818.
0
Attacker Value
Unknown

CVE-2015-4280

Disclosure Date: July 18, 2015 (last updated October 05, 2023)
Cisco Prime Collaboration Assurance 10.0 allows remote attackers to cause a denial of service (HTTP service outage) via a crafted HTTP request, aka Bug ID CSCum38844.
0
Attacker Value
Unknown

CVE-2015-4188

Disclosure Date: June 17, 2015 (last updated October 05, 2023)
SQL injection vulnerability in the Manager interface in Cisco Prime Collaboration 10.5(1) allows remote attackers to execute arbitrary SQL commands via a crafted URL, aka Bug IDs CSCuu29910, CSCuu29928, and CSCuu59104.
0
Attacker Value
Unknown

CVE-2015-4190

Disclosure Date: June 17, 2015 (last updated October 05, 2023)
Cisco Cloud Portal in Cisco Prime Service Catalog 9.4.1_vortex on Cloud Portal appliances allows man-in-the-middle attackers to modify data via unspecified vectors, aka Bug ID CSCuh19683.
0