CVE-2010-0139
published 2010-01-28CVE-2010-0139: Cisco Unified MeetingPlace 7 before 7.0(2.3) hotfix 5F, 6 before 6.0.639.2, and possibly 5 does not properly validate SQL commands, which allows remote…
PriorityP342critical9CVSS 2.0
AVNACLAuNCPIPAC
EPSS
2.01%
78.7th percentile
Cisco Unified MeetingPlace 7 before 7.0(2.3) hotfix 5F, 6 before 6.0.639.2, and possibly 5 does not properly validate SQL commands, which allows remote attackers to create, modify, or delete data in a database via unspecified vectors, aka Bug ID CSCtc39691.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_meetingplace | — | — |
| cisco | unified_meetingplace | — | — |
| cisco | unified_meetingplace | — | — |
| cisco | unified_meetingplace | — | — |
| cisco | unified_meetingplace | — | — |
| cisco | unified_meetingplace | — | — |
| cisco | unified_meetingplace | — | — |
| cisco | unified_meetingplace | — | — |
| cisco | unified_meetingplace | — | — |
CVSS provenance
nvdv2.09.0CRITICALAV:N/AC:L/Au:N/C:P/I:P/A:C
vendor_cisco10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Multiple Vulnerabilities in Cisco Unified MeetingPlace
vendor_cisco·2010-01-27·CVSS 10.0
CVE-2010-0139 [CRITICAL] CWE-200 Multiple Vulnerabilities in Cisco Unified MeetingPlace
Multiple Vulnerabilities in Cisco Unified MeetingPlace
Multiple vulnerabilities exist in Cisco Unified MeetingPlace. This
security advisory outlines the details of these vulnerabilities:
Insufficient validation of SQL commands
Unauthorized account creation
User and password enumeration in Cisco MeetingTime
Privilege escalation in Cisco MeetingTime
Workarounds are not available for these vulnerabilities.
This advisory is posted at
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20100127-mp.
Cisco
Multiple Vulnerabilities in Cisco Unified MeetingPlace
vendor_cisco
CVE-2010-0139 Multiple Vulnerabilities in Cisco Unified MeetingPlace
CVE-2010-0139: Multiple Vulnerabilities in Cisco Unified MeetingPlace
Multiple vulnerabilities exist in Cisco Unified MeetingPlace. This security advisory outlines the
CWE: CWE-200, CWE-264, CWE-287, CWE-200, CWE-264, CWE-287
Bug IDs: CSCtc39691, CSCtc59231, CSCtd40661, CSCsv76935, CSCsv66530
GHSA
GHSA-2rfx-cf2v-2f6c: Cisco Unified MeetingPlace 7 before 7
ghsa_unreviewed·2022-05-02
CVE-2010-0139 [HIGH] CWE-89 GHSA-2rfx-cf2v-2f6c: Cisco Unified MeetingPlace 7 before 7
Cisco Unified MeetingPlace 7 before 7.0(2.3) hotfix 5F, 6 before 6.0.639.2, and possibly 5 does not properly validate SQL commands, which allows remote attackers to create, modify, or delete data in a database via unspecified vectors, aka Bug ID CSCtc39691.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2010-01-28
Published