
CVE-2018-0124
https://notcve.org/view.php?id=CVE-2018-0124
22 Feb 2018 — A vulnerability in Cisco Unified Communications Domain Manager could allow an unauthenticated, remote attacker to bypass security protections, gain elevated privileges, and execute arbitrary code. The vulnerability is due to insecure key generation during application configuration. An attacker could exploit this vulnerability by using a known insecure key value to bypass security protections by sending arbitrary requests using the insecure key to a targeted application. An exploit could allow the attacker t... • http://www.securityfocus.com/bid/103114 • CWE-320: Key Management Errors •

CVE-2017-6668
https://notcve.org/view.php?id=CVE-2017-6668
13 Jun 2017 — Vulnerabilities in the web-based GUI of Cisco Unified Communications Domain Manager (CUCDM) could allow an authenticated, remote attacker to impact the confidentiality of the system by executing arbitrary SQL queries, aka SQL Injection. More Information: CSCvc52784 CSCvc97648. Known Affected Releases: 8.1(7)ER1. Vulnerabilidades en la GUI basada en web de Cisco Unified Communications Domain Manager (CUCDM), podrían permitir a un atacante autenticado y remoto afectar la confidencialidad del sistema mediante ... • http://www.securityfocus.com/bid/98947 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2017-6670
https://notcve.org/view.php?id=CVE-2017-6670
13 Jun 2017 — A vulnerability in the web-based GUI of Cisco Unified Communications Domain Manager could allow an unauthenticated, remote attacker to redirect a user to a malicious web page, aka an Open Redirect issue. More Information: CSCvc54813. Known Affected Releases: 8.1(7)ER1. Una vulnerabilidad en la GUI basada en web de Cisco Unified Communications Domain Manager, podría permitir a un atacante remoto no autenticado redireccionar a un usuario hacia una página web maliciosa, también se conoce como un problema de Re... • http://www.securityfocus.com/bid/98946 • CWE-601: URL Redirection to Untrusted Site ('Open Redirect') •

CVE-2016-1354
https://notcve.org/view.php?id=CVE-2016-1354
03 Mar 2016 — Cross-site scripting (XSS) vulnerability in Cisco Unified Communications Domain Manager (UCDM) 8.x before 8.1.1 allows remote attackers to inject arbitrary web script or HTML via crafted markup data, aka Bug ID CSCud41176. Vulnerabilidad de XSS en Cisco Unified Communications Domain Manager (UCDM) 8.x en versiones anteriores a 8.1.1 permite a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarios a través de datos markup manipulados, también conocida como Bug ID CSCud41176. • http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160302-cucdm • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2015-4196
https://notcve.org/view.php?id=CVE-2015-4196
04 Jul 2015 — Platform Software before 4.4.5 in Cisco Unified Communications Domain Manager (CDM) 8.x has a hardcoded password for a privileged account, which allows remote attackers to obtain root access by leveraging knowledge of this password and entering it in an SSH session, aka Bug ID CSCuq45546. Platform Software anterior a 4.4.5 en Cisco Unified Communications Domain Manager (CDM) 8.x tiene una contraseña embebida para una cuenta privilegiada, lo que permite a atacantes remotos obtener el acceso a root mediante e... • http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150701-cucdm • CWE-255: Credentials Management Errors •

CVE-2015-0682
https://notcve.org/view.php?id=CVE-2015-0682
03 Apr 2015 — Cisco Unified Communications Domain Manager 8.1(4) allows remote authenticated users to execute arbitrary code by visiting a "deprecated page," aka Bug ID CSCup90168. Cisco Unified Communications Domain Manager 8.1(4) permite a usuarios remotos autenticados ejecutar código arbitrario mediante la visita a una 'página obsoleta,' también conocido como Bug ID CSCup90168. • http://tools.cisco.com/security/center/viewAlert.x?alertId=38113 • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2015-0683
https://notcve.org/view.php?id=CVE-2015-0683
03 Apr 2015 — Cisco Unified Communications Domain Manager 8.1(4) allows remote authenticated users to obtain sensitive information via a file-inclusion attack, aka Bug ID CSCup94744. Cisco Unified Communications Domain Manager 8.1(4) permite a usuarios remotos autenticados obtener información sensible a través de un ataque de inclusión de ficheros, también conocido como Bug ID CSCup94744. • http://tools.cisco.com/security/center/viewAlert.x?alertId=38118 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2015-0684
https://notcve.org/view.php?id=CVE-2015-0684
03 Apr 2015 — SQL injection vulnerability in the Image Management component in Cisco Unified Communications Domain Manager 8.1(4) allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCuq52515. Vulnerabilidad de inyección SQL en el componente Image Management en Cisco Unified Communications Domain Manager 8.1(4) permite a usuarios remotos autenticados ejecutar comandos SQL arbitrarios a través de vectores no especificados, también conocido como Bug ID CSCuq52515. • http://tools.cisco.com/security/center/viewAlert.x?alertId=38114 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2014-8018
https://notcve.org/view.php?id=CVE-2014-8018
22 Dec 2014 — Multiple cross-site scripting (XSS) vulnerabilities in Business Voice Services Manager (BVSM) pages in the Application Software in Cisco Unified Communications Domain Manager 8 allow remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug IDs CSCur19651, CSCur18555, CSCur19630, and CSCur19661. Múltiples vulnerabilidades XSS en BetkQ Access Manager (NAM) 4.x anterior a 4.1 permite a atacantes remotos inyectar scripts o HTML arbitrario mediante (1) un parámetro arbitrario hacia roma... • http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-8018 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2014-8010
https://notcve.org/view.php?id=CVE-2014-8010
10 Dec 2014 — The web framework in Cisco Unified Communications Domain Manager 8 allows remote authenticated administrators to execute arbitrary OS commands via crafted values, aka Bug ID CSCuq50205. El Framework web en Cisco Unified Communications Domain Manager 8 permite a administradores remotos autenticados ejecutar comandos OS arbitrarios a través de valores manipulados, también conocido como Bug ID CSCuq50205. • http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-8010 • CWE-20: Improper Input Validation •