CVE-2016-1439

Cross-site scripting (XSS) vulnerability in the management interface in Cisco Unified Contact Center Enterprise through 10.5(2) allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCux59650.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.1 MEDIUM
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
ciscoCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 48%
VendorProductVersion
ciscounified_contact_center_enterprise
4.6\(2\):sr1
ciscounified_contact_center_enterprise
4.6\(2\):sr2
ciscounified_contact_center_enterprise
4.6\(2\):sr3
ciscounified_contact_center_enterprise
4.6\(2\):sr4
ciscounified_contact_center_enterprise
4.6\(2\):sr5
ciscounified_contact_center_enterprise
4.6\(2\):sr6
ciscounified_contact_center_enterprise
4.6.2
ciscounified_contact_center_enterprise
5.0\(0\)
ciscounified_contact_center_enterprise
5.0\(0\):sr10
ciscounified_contact_center_enterprise
5.0\(0\):sr11
ciscounified_contact_center_enterprise
5.0\(0\):sr12
ciscounified_contact_center_enterprise
5.0\(0\):sr13
ciscounified_contact_center_enterprise
5.0\(0\):sr2
ciscounified_contact_center_enterprise
5.0\(0\):sr3
ciscounified_contact_center_enterprise
5.0\(0\):sr4
ciscounified_contact_center_enterprise
5.0\(0\):sr5
ciscounified_contact_center_enterprise
5.0\(0\):sr7
ciscounified_contact_center_enterprise
5.0\(0\):sr8
ciscounified_contact_center_enterprise
5.0\(0\):sr9
ciscounified_contact_center_enterprise
6.0\(0\):sr1
ciscounified_contact_center_enterprise
6.0\(0\):sr10
ciscounified_contact_center_enterprise
6.0\(0\):sr11
ciscounified_contact_center_enterprise
6.0\(0\):sr12
ciscounified_contact_center_enterprise
6.0\(0\):sr2
ciscounified_contact_center_enterprise
6.0\(0\):sr3
ciscounified_contact_center_enterprise
6.0\(0\):sr4
ciscounified_contact_center_enterprise
6.0\(0\):sr5
ciscounified_contact_center_enterprise
6.0\(0\):sr6
ciscounified_contact_center_enterprise
6.0\(0\):sr7
ciscounified_contact_center_enterprise
6.0\(0\):sr8
ciscounified_contact_center_enterprise
6.0\(0\):sr9
ciscounified_contact_center_enterprise
7.0\(0\):sr1
ciscounified_contact_center_enterprise
7.0\(0\):sr2
ciscounified_contact_center_enterprise
7.0\(0\):sr3
ciscounified_contact_center_enterprise
7.0\(0\):sr4
ciscounified_contact_center_enterprise
7.1\(2\)
ciscounified_contact_center_enterprise
7.1\(3\)
ciscounified_contact_center_enterprise
7.1\(4\)
ciscounified_contact_center_enterprise
7.1\(5\)
ciscounified_contact_center_enterprise
7.1.0
ciscounified_contact_center_enterprise
7.2\(1\)
ciscounified_contact_center_enterprise
7.2\(2\)
ciscounified_contact_center_enterprise
7.2\(3\)
ciscounified_contact_center_enterprise
7.2\(4\)
ciscounified_contact_center_enterprise
7.2\(5\)
ciscounified_contact_center_enterprise
7.2\(6\)
ciscounified_contact_center_enterprise
7.2\(7\)
ciscounified_contact_center_enterprise
7.5\(2\)
ciscounified_contact_center_enterprise
7.5\(3\)
ciscounified_contact_center_enterprise
7.5\(4\)
ciscounified_contact_center_enterprise
7.5\(5\)
ciscounified_contact_center_enterprise
7.5\(6\)
ciscounified_contact_center_enterprise
7.5\(7\)
ciscounified_contact_center_enterprise
7.5\(8\)
ciscounified_contact_center_enterprise
7.5\(9\)
ciscounified_contact_center_enterprise
7.5\(10\)
ciscounified_contact_center_enterprise
8.0\(2\)
ciscounified_contact_center_enterprise
8.0\(3\)
ciscounified_contact_center_enterprise
8.5\(1\)
ciscounified_contact_center_enterprise
8.5\(2\)
ciscounified_contact_center_enterprise
8.5\(3\)
ciscounified_contact_center_enterprise
8.5\(4\)
ciscounified_contact_center_enterprise
9.0\(2\)
ciscounified_contact_center_enterprise
9.0\(3\)
ciscounified_contact_center_enterprise
9.0\(4\)
ciscounified_contact_center_enterprise
10.0\(1\)
ciscounified_contact_center_enterprise
10.0\(2\)
ciscounified_contact_center_enterprise
10.5\(1\)
ciscounified_contact_center_enterprise
10.5\(2\)
𝑥
= Vulnerable software versions