10
CVSSv2

CVE-2010-0140

Published: 28/01/2010 Updated: 31/01/2010
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Multiple unspecified vulnerabilities in the web server in Cisco Unified MeetingPlace 7 prior to 7.0(2.3) hotfix 5F, 6 prior to 6.0.639.3, and possibly 5 allow remote malicious users to create (1) user or (2) administrator accounts via a crafted URL in a request to the internal interface, aka Bug IDs CSCtc59231 and CSCtd40661.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco unified meetingplace 5.2

cisco unified meetingplace 5.4

cisco unified meetingplace 7.0

cisco unified meetingplace 7.0.1

cisco unified meetingplace 6.0

cisco unified meetingplace 5.3

cisco unified meetingplace 7.0.2

Vendor Advisories

Multiple vulnerabilities exist in Cisco Unified MeetingPlace This security advisory outlines the details of these vulnerabilities: Insufficient validation of SQL commands Unauthorized account creation User and password enumeration in Cisco MeetingTime Privilege escalation in Cisco MeetingTime Workaroun ...