CVE-2015-4294
01.08.2015, 01:59
Cross-site scripting (XSS) vulnerability in Cisco IM and Presence Service before 10.5 MR1 allows remote attackers to inject arbitrary web script or HTML by constructing a crafted URL that leverages incomplete filtering of HTML elements, aka Bug ID CSCut41766.
Vendor | Product | Version |
---|---|---|
cisco | unified_communications_manager_im_and_presence_service | 9.0\(1\) |
cisco | unified_communications_manager_im_and_presence_service | 9.1\(1\) |
cisco | unified_communications_manager_im_and_presence_service | 10.5\(1\) |
𝑥
= Vulnerable software versions