First published: Tue Apr 21 2015(Updated: )
Unrestricted file upload vulnerability in the Custom Prompts upload implementation in Cisco Unified MeetingPlace 8.6(1.9) allows remote authenticated users to execute arbitrary code by using the languageShortName parameter to upload a file that provides shell access, aka Bug ID CSCus95712.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Unified MeetingPlace | =8.6\(1.9\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-0702 is considered a critical vulnerability due to the potential for arbitrary code execution.
To fix CVE-2015-0702, you should apply the latest security updates provided by Cisco for Unified MeetingPlace 8.6(1.9).
CVE-2015-0702 affects remote authenticated users of Cisco Unified MeetingPlace 8.6(1.9) due to the unrestricted file upload feature.
CVE-2015-0702 allows attackers to upload files that could provide shell access, potentially leading to complete system compromise.
There are no known workarounds for CVE-2015-0702, so applying the security update is essential to mitigate the vulnerability.