6.4
CVSSv2

CVE-2010-0141

Published: 28/01/2010 Updated: 07/01/2011
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

MeetingTime in Cisco Unified MeetingPlace 6 before MR5, and possibly 5, allows remote malicious users to discover usernames, passwords, and unspecified other data from the user database via a modified authentication sequence to the Audio Server, aka Bug ID CSCsv76935.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco unified meetingplace 6.0

cisco unified meetingplace 6.0.170.0

cisco unified meetingplace 6.0.244

Vendor Advisories

Multiple vulnerabilities exist in Cisco Unified MeetingPlace This security advisory outlines the details of these vulnerabilities: Insufficient validation of SQL commands Unauthorized account creation User and password enumeration in Cisco MeetingTime Privilege escalation in Cisco MeetingTime Workaroun ...