Vulnerability Details CVE-2016-6370
Directory traversal vulnerability in the web interface in Cisco Hosted Collaboration Mediation Fulfillment (HCM-F) 10.6(3) and earlier allows remote authenticated users to read arbitrary files via a crafted pathname in an HTTP request, aka Bug ID CSCuz27255.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 66.5%
CVSS Severity
CVSS v3 Score 4.3
CVSS v2 Score 4.0
Products affected by CVE-2016-6370
-
cpe:2.3:a:cisco:hosted_collaboration_mediation_fulfillment:10.6(1)_base
-
cpe:2.3:a:cisco:hosted_collaboration_mediation_fulfillment:10.6(2)_base
-
cpe:2.3:a:cisco:hosted_collaboration_mediation_fulfillment:10.6(3)_base