CVE-2010-0140

Cisco Unified MeetingPlace <7.0(2.3) - RCE

Title source: llm
STIX 2.1

Description

Multiple unspecified vulnerabilities in the web server in Cisco Unified MeetingPlace 7 before 7.0(2.3) hotfix 5F, 6 before 6.0.639.3, and possibly 5 allow remote attackers to create (1) user or (2) administrator accounts via a crafted URL in a request to the internal interface, aka Bug IDs CSCtc59231 and CSCtd40661.

References (2)

Core 2
Core References
Patch, Vendor Advisory vendor-advisory x_refsource_cisco
http://www.cisco.com/en/US/products/products_security_advisory09186a0080b1490b.shtml
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/37965

Scores

EPSS 0.0263
EPSS Percentile 83.9%

Details

Status published
Products (7)
cisco/unified_meetingplace 5.2
cisco/unified_meetingplace 5.3
cisco/unified_meetingplace 5.4
cisco/unified_meetingplace 6.0
cisco/unified_meetingplace 7.0
cisco/unified_meetingplace 7.0.1
cisco/unified_meetingplace 7.0.2
Published Jan 28, 2010
Tracked Since Feb 18, 2026