CVE-2013-5528
43Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 23%
from disclosure to weapon1153 days
Published on NVDOct 11
1st PoC+1153d
exploitation probability
23%top 2% of all CVEs
observed exploitation
nono source reports it
3 public exploit(s)
Directory traversal vulnerability in the Tomcat administrative web interface in Cisco Unified Communications Manager allows remote authenticated users to read arbitrary files via directory traversal sequences in an unspecified input string, aka Bug ID CSCui78815.
Affected products
n/a · n/apublic PoCs found — 3
exploitdbwww.exploit-db.com/exploits/40887unverifiedcve_referencepacketstormsecurity.com/files/140071/Cisco-Unified-Communications-Manager-7-8-9-Directory-Traversal.htmlunverifiedcve_referencewww.exploit-db.com/exploits/40887/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://osvdb.org/98336http://packetstormsecurity.com/files/140071/Cisco-Unified-Communications-Manager-7-8-9-Directory-Traversal.htmlhttps://www.exploit-db.com/exploits/40887/http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-5528http://www.securityfocus.com/bid/62960