Cisco Unified MeetingPlace Web Conferencing Authentication Bypass Vulnerability
BID:33901
Info
Cisco Unified MeetingPlace Web Conferencing Authentication Bypass Vulnerability
| Bugtraq ID: | 33901 |
| Class: | Access Validation Error |
| CVE: |
CVE-2009-0614 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 25 2009 12:00AM |
| Updated: | Feb 25 2009 08:57PM |
| Credit: | National Australia Bank's Security Assurance Team |
| Vulnerable: |
Cisco Unified MeetingPlace Web Conferencing 7.0 Cisco Unified MeetingPlace Web Conference 6.0.244 .1A Cisco Unified MeetingPlace Web Conference 6.0.170.0 |
| Not Vulnerable: |
Cisco Unified MeetingPlace Web Conferencing 7.0.2 Cisco Unified MeetingPlace Web Conferencing 6.0.517 .0 |
Discussion
Cisco Unified MeetingPlace Web Conferencing Authentication Bypass Vulnerability
Cisco Unified MeetingPlace Web Conferencing is prone to an unspecified authentication-bypass vulnerability.
An attacker can exploit this issue to gain administrative access to the affected application. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.
This issue is tracked by Cisco Bug ID CSCsv65815.
Unified MeetingPlace Web Conferencing 6.0 and 7.0 are vulnerable.
Cisco Unified MeetingPlace Web Conferencing is prone to an unspecified authentication-bypass vulnerability.
An attacker can exploit this issue to gain administrative access to the affected application. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.
This issue is tracked by Cisco Bug ID CSCsv65815.
Unified MeetingPlace Web Conferencing 6.0 and 7.0 are vulnerable.
Exploit / POC
Cisco Unified MeetingPlace Web Conferencing Authentication Bypass Vulnerability
Attackers can exploit this issue via a browser.
Attackers can exploit this issue via a browser.
Solution / Fix
Cisco Unified MeetingPlace Web Conferencing Authentication Bypass Vulnerability
Solution:
The vendor has released updates. Please contact the vendor for details.
Solution:
The vendor has released updates. Please contact the vendor for details.
References
Cisco Unified MeetingPlace Web Conferencing Authentication Bypass Vulnerability
References:
References: