First published: Thu Jan 28 2010(Updated: )
Multiple unspecified vulnerabilities in the web server in Cisco Unified MeetingPlace 7 before 7.0(2.3) hotfix 5F, 6 before 6.0.639.3, and possibly 5 allow remote attackers to create (1) user or (2) administrator accounts via a crafted URL in a request to the internal interface, aka Bug IDs CSCtc59231 and CSCtd40661.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Unified MeetingPlace | =5.3 | |
Cisco Unified MeetingPlace | =7.0 | |
Cisco Unified MeetingPlace | =7.0.1 | |
Cisco Unified MeetingPlace | =5.2 | |
Cisco Unified MeetingPlace | =7.0.2 | |
Cisco Unified MeetingPlace | =5.4 | |
Cisco Unified MeetingPlace | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-0140 has a high severity rating due to the potential for remote account creation.
To fix CVE-2010-0140, upgrade Cisco Unified MeetingPlace to versions 7.0(2.3) hotfix 5F or 6.0.639.3 or later.
CVE-2010-0140 affects versions 5.2, 5.3, 5.4, 6.0, 7.0, and 7.0.1 of Cisco Unified MeetingPlace.
CVE-2010-0140 allows remote attackers to create both user and administrator accounts.
CVE-2010-0140 is a remote command injection vulnerability that can be exploited via crafted URLs.