Arbitrary File Upload Vulnerability in Cisco Unified Contact Center Express (Bug ID CSCun74133)
CVE-2014-2180 · MEDIUM Severity
AV:N/AC:L/AU:S/C:N/I:P/A:N
The Document Management component in Cisco Unified Contact Center Express does not properly validate a parameter, which allows remote authenticated users to upload files to arbitrary pathnames via a crafted HTTP request, aka Bug ID CSCun74133.
Learn more about our Cis Benchmark Audit For Cisco.