CVE漏洞中文网

0DayBank一个专门收集整理全球互联网漏洞的公开发布网站
  1. 首页
  2. CVE
  3. 正文

CVE-2016-6440 Cisco Unified Communications Manager iFrame Data Clickjacking Vulnerability (cisco-sa-20161012-ucm)

2016年10月25日 1548点热度 0人点赞 0条评论

漏洞类别:Cisco

漏洞等级:

漏洞信息

The Cisco Unified Communications Manager (CUCM) may be vulnerable to data that can be displayed inside an iframe within a web page, which in turn could lead to a clickjacking attack.
The vulnerability is due to a lack of proper input sanitization of iframe data within the HTTP requests sent to the device.

漏洞危害

An attacker could exploit this vulnerability by sending crafted HTTP packets with malicious iframe data. An exploit could allow the attacker to perform a clickjacking or phishing attack where the user is tricked into clicking on a malicious link.

解决方案

Cisco has released fixes to resolve these vulnerabilities. Refer cisco-sa-20161012-ucm to obtain more information.

Patch:
Following are links for downloading patches to fix the vulnerabilities:

cisco-sa-20161012-ucm: Cisco Unified Communications Manager

0day

标签: 暂无
最后更新:2016年10月25日

小助手

这个人很懒,什么都没留下

点赞
< 上一篇
下一篇 >

文章评论

您需要 登录 之后才可以评论

COPYRIGHT © 2024 www.pdr.cn CVE漏洞中文网. ALL RIGHTS RESERVED.

鲁ICP备2022031030号

联系邮箱:wpbgssyubnmsxxxkkk@proton.me