CVE-2017-12214
https://notcve.org/view.php?id=CVE-2017-12214
A vulnerability in the Operations, Administration, Maintenance, and Provisioning (OAMP) credential reset functionality for Cisco Unified Customer Voice Portal (CVP) could allow an authenticated, remote attacker to gain elevated privileges. The vulnerability is due to a lack of proper input validation. An attacker could exploit this vulnerability by authenticating to the OAMP and sending a crafted HTTP request. A successful exploit could allow the attacker to gain administrator privileges. The attacker must successfully authenticate to the system to exploit this vulnerability. • http://www.securityfocus.com/bid/100931 http://www.securitytracker.com/id/1039411 https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170920-cvp • CWE-20: Improper Input Validation CWE-264: Permissions, Privileges, and Access Controls •
CVE-2015-0735
https://notcve.org/view.php?id=CVE-2015-0735
Cross-site request forgery (CSRF) vulnerability in Cisco Unified Customer Voice Portal (CVP) 10.5(1) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCut93970. Vulnerabilidad de CSRF en Cisco Unified Customer Voice Portal (CVP) 10.5(1) permite a atacantes remotos secuestrar la autenticación de usuarios arbitrarios, también conocido como Bug ID CSCut93970. • http://tools.cisco.com/security/center/viewAlert.x?alertId=38868 http://www.securitytracker.com/id/1032340 • CWE-352: Cross-Site Request Forgery (CSRF) •