CVE-2013-1169
Cisco Unified MeetingPlace Web Conferencing Server 7.x-8.5 - Authentication Bypass via Cookie Manipulation
Title source: llmDescription
Cisco Unified MeetingPlace Web Conferencing Server 7.x before 7.1MR1 Patch 2, 8.0 before 8.0MR1 Patch 2, and 8.5 before 8.5MR3 Patch 1, when the Remember Me option is used, does not properly verify cookies, which allows remote attackers to impersonate users via a crafted login request, aka Bug ID CSCuc64846.
References (1)
Core 1
Core References
Vendor Advisory vendor-advisory
x_refsource_cisco
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130410-mp
Scores
EPSS
0.0184
EPSS Percentile
76.8%
Details
CWE
CWE-264
Status
published
Products (3)
cisco/unified_meetingplace_web_conferencing_server
7.1
cisco/unified_meetingplace_web_conferencing_server
8.0
cisco/unified_meetingplace_web_conferencing_server
8.5
Published
Apr 11, 2013
Tracked Since
Feb 18, 2026