10
CVSSv2

CVE-2011-0385

Published: 25/02/2011 Updated: 17/08/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

The administrative web interface on Cisco TelePresence Recording Server devices with software 1.6.x and Cisco TelePresence Multipoint Switch (CTMS) devices with software 1.0.x, 1.1.x, 1.5.x, and 1.6.x allows remote malicious users to create or overwrite arbitrary files, and possibly execute arbitrary code, via a crafted request, aka Bug IDs CSCth85786 and CSCth61065.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco telepresence_recording_server_software 1.6.1

cisco telepresence_recording_server_software 1.6.2

cisco telepresence_recording_server_software 1.6.3

cisco telepresence_recording_server

cisco telepresence_multipoint_switch_software 1.5.0

cisco telepresence_multipoint_switch_software 1.1.2

cisco telepresence_multipoint_switch_software 1.5.6

cisco telepresence_multipoint_switch_software 1.6.0

cisco telepresence_multipoint_switch_software 1.6.3

cisco telepresence_multipoint_switch_software 1.6.4

cisco telepresence_multipoint_switch_software 1.5.2

cisco telepresence_multipoint_switch_software 1.5.3

cisco telepresence_multipoint_switch_software 1.5.1

cisco telepresence_multipoint_switch_software 1.6.1

cisco telepresence_multipoint_switch_software 1.6.2

cisco telepresence_multipoint_switch_software 1.1.1

cisco telepresence_multipoint_switch_software 1.1.0

cisco telepresence_multipoint_switch_software 1.0.4.0

cisco telepresence_multipoint_switch_software 1.5.4

cisco telepresence_multipoint_switch_software 1.5.5

cisco telepresence_multipoint_switch

Vendor Advisories

Multiple vulnerabilities exist within the Cisco TelePresence Recording Server This security advisory outlines details of the following vulnerabilities: Unauthenticated Java Servlet Access Common Gateway Interface (CGI) Command Injection Unauthenticated Arbitrary File Upload XML-Remote Procedure Call ...
Multiple vulnerabilities exist within the Cisco TelePresence Multipoint Switch This security advisory outlines details of the following vulnerabilities: Unauthenticated Java Servlet Access Unauthenticated Arbitrary File Upload Cisco Discovery Protocol Remote Code Execution Unauthorized Servlet Access Jav ...