Description
Multiple unspecified vulnerabilities in the web server in Cisco Unified MeetingPlace 7 before 7.0(2.3) hotfix 5F, 6 before 6.0.639.3, and possibly 5 allow remote attackers to create (1) user or (2) administrator accounts via a crafted URL in a request to the internal interface, aka Bug IDs CSCtc59231 and CSCtd40661.
References (2)
Core 2
Core References
Patch, Vendor Advisory vendor-advisory
x_refsource_cisco
http://www.cisco.com/en/US/products/products_security_advisory09186a0080b1490b.shtml
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/37965
Scores
EPSS
0.0263
EPSS Percentile
83.9%
Details
Status
published
Products (7)
cisco/unified_meetingplace
5.2
cisco/unified_meetingplace
5.3
cisco/unified_meetingplace
5.4
cisco/unified_meetingplace
6.0
cisco/unified_meetingplace
7.0
cisco/unified_meetingplace
7.0.1
cisco/unified_meetingplace
7.0.2
Published
Jan 28, 2010
Tracked Since
Feb 18, 2026