NVD

Id
25792  
Name
CVE-2015-4328  
Description
Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.2 improperly checks for a user account"s read-only attribute, which allows remote authenticated users to execute arbitrary OS commands via crafted HTTP requests, as demonstrated by read or write operations on the Unified Communications lookup page, aka Bug ID CSCuv12552.  
Reject
 
CVSS Version
2  
CVSS Score
4  
Severity
Medium  
CVSS Base Score
4  
CVSS Impact Subscore
2.9  
CVSS Exploit Subscore
8  
CVSS Vector
(AV:N/AC:L/Au:S/C:N/I:P/A:N)  
Pub Date
2017-01-19  
Published
2015-08-19  
Modified Date
2017-01-04  
Seq
2015-4328  

Actions