vendor:
Unity Express
by:
Jacob Holcomb of Independent Security Evaluators
N/A
CVSS
N/A
XSS and CSRF
CWE
Product Name: Unity Express
Affected Version From:
Affected Version To:
Patch Exists: Unknown
Related CWE: CVE-2013-1114, CVE-2013-1120
CPE:
Platforms Tested:
2012
Cisco Unity Express Multiple Vulnerabilities
This exploit allows for reflective XSS and information disclosure in Cisco Unity Express. The XSS vulnerability is identified as CVE-2013-1114 and the CSRF vulnerability is identified as CVE-2013-1120.