CVE-2016-1434

The license-certificate upload functionality on Cisco 8800 phones with software 11.0(1) allows remote authenticated users to delete arbitrary files via an invalid file, aka Bug ID CSCuz03010.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

AND
cpe:2.3:h:cisco:ip_phone_8800:-:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ip_phone_8800_series_firmware:11.0\(1\):*:*:*:*:*:*:*

Information

Published : 2016-06-22 17:59

Updated : 2016-11-29 19:04


NVD link : CVE-2016-1434

Mitre link : CVE-2016-1434


JSON object : View

CWE
CWE-20

Improper Input Validation

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Advertisement

dedicated server usa

Products Affected

cisco

  • ip_phone_8800_series_firmware
  • ip_phone_8800