Vulnerabilities > Cisco > Unity Express Software > 2.1.2
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2013-02-13 | CVE-2013-1114 | Cross-Site Scripting vulnerability in Cisco Unity Express Software Multiple cross-site scripting (XSS) vulnerabilities in Cisco Unity Express before 8.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CSCud87527. | 4.3 |
2013-02-06 | CVE-2013-1120 | Cross-Site Request Forgery (CSRF) vulnerability in Cisco Unity Express and Unity Express Software Multiple cross-site request forgery (CSRF) vulnerabilities on the Cisco Unity Express with software before 8.0 allow remote attackers to hijack the authentication of unspecified victims via unknown vectors, aka Bug ID CSCue35910. | 6.8 |