9
CVSSv2

CVE-2010-0139

Published: 28/01/2010 Updated: 07/01/2011
CVSS v2 Base Score: 9 | Impact Score: 8.5 | Exploitability Score: 10
VMScore: 801
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:C

Vulnerability Summary

Cisco Unified MeetingPlace 7 prior to 7.0(2.3) hotfix 5F, 6 prior to 6.0.639.2, and possibly 5 does not properly validate SQL commands, which allows remote malicious users to create, modify, or delete data in a database via unspecified vectors, aka Bug ID CSCtc39691.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cisco unified meetingplace 5.0

cisco unified meetingplace 7.0

cisco unified meetingplace 7.0.2

cisco unified meetingplace 5

cisco unified meetingplace 6.0.170.0

cisco unified meetingplace 6.0.244

cisco unified meetingplace 6.0

cisco unified meetingplace 7.0.1

Vendor Advisories

Multiple vulnerabilities exist in Cisco Unified MeetingPlace This security advisory outlines the details of these vulnerabilities: Insufficient validation of SQL commands Unauthorized account creation User and password enumeration in Cisco MeetingTime Privilege escalation in Cisco MeetingTime Workaroun ...