Record summary

CVE-2014-3300 has a selected CVSS score of 7.5; EIP currently links 2 catalogued exploits.

Description

The BVSMWeb portal in the web framework in Cisco Unified Communications Domain Manager (CDM) in Unified CDM Application Software before 10 does not properly implement access control, which allows remote attackers to modify user information via a crafted URL, aka Bug ID CSCum77041.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
2

Proofs of concept

2

Catalogued exploits

MetasploitViproy CUCDM IP Phone XML Services - Call Forwarding ToolMetasploit auxiliary PoCby fozavciNot analyzed1 file

Ruby

Metasploit

PoC details
MetasploitViproy CUCDM IP Phone XML Services - Speed Dial Attack ToolMetasploit auxiliary PoCby fozavciNot analyzed1 file

Ruby

Metasploit

PoC details

References

6