Cisco Unified MeetingPlace Web Conferencing Server 7.x prior to 7.1MR1 Patch 2, 8.0 prior to 8.0MR1 Patch 2, and 8.5 prior to 8.5MR3 Patch 1, when the Remember Me option is used, does not properly verify cookies, which allows remote malicious users to impersonate users via a crafted login request, aka Bug ID CSCuc64846.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
cisco unified meetingplace web conferencing server 7.1 |
||
cisco unified meetingplace web conferencing server 8.0 |
||
cisco unified meetingplace web conferencing server 8.5 |