CVE-2010-0141
published 2010-01-28CVE-2010-0141: MeetingTime in Cisco Unified MeetingPlace 6 before MR5, and possibly 5, allows remote attackers to discover usernames, passwords, and unspecified other data…
PriorityP336medium6.4CVSS 2.0
AVNACLAuNCPIPAN
EPSS
1.08%
61.2th percentile
MeetingTime in Cisco Unified MeetingPlace 6 before MR5, and possibly 5, allows remote attackers to discover usernames, passwords, and unspecified other data from the user database via a modified authentication sequence to the Audio Server, aka Bug ID CSCsv76935.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_meetingplace | — | — |
| cisco | unified_meetingplace | — | — |
| cisco | unified_meetingplace | — | — |
| cisco | unified_meetingplace | — | — |
CVSS provenance
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
vendor_cisco10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Multiple Vulnerabilities in Cisco Unified MeetingPlace
vendor_cisco·2010-01-27·CVSS 10.0
CVE-2010-0139 [CRITICAL] CWE-200 Multiple Vulnerabilities in Cisco Unified MeetingPlace
Multiple Vulnerabilities in Cisco Unified MeetingPlace
Multiple vulnerabilities exist in Cisco Unified MeetingPlace. This
security advisory outlines the details of these vulnerabilities:
Insufficient validation of SQL commands
Unauthorized account creation
User and password enumeration in Cisco MeetingTime
Privilege escalation in Cisco MeetingTime
Workarounds are not available for these vulnerabilities.
This advisory is posted at
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20100127-mp.
Cisco
Multiple Vulnerabilities in Cisco Unified MeetingPlace
vendor_cisco
CVE-2010-0141 Multiple Vulnerabilities in Cisco Unified MeetingPlace
CVE-2010-0141: Multiple Vulnerabilities in Cisco Unified MeetingPlace
Multiple vulnerabilities exist in Cisco Unified MeetingPlace. This security advisory outlines the
CWE: CWE-200, CWE-264, CWE-287, CWE-200, CWE-264, CWE-287
Bug IDs: CSCtc39691, CSCtc59231, CSCtd40661, CSCsv76935, CSCsv66530
GHSA
GHSA-67cg-hqpj-xmm9: MeetingTime in Cisco Unified MeetingPlace 6 before MR5, and possibly 5, allows remote attackers to discover usernames, passwords, and unspecified othe
ghsa_unreviewed·2022-05-02
CVE-2010-0141 [MEDIUM] GHSA-67cg-hqpj-xmm9: MeetingTime in Cisco Unified MeetingPlace 6 before MR5, and possibly 5, allows remote attackers to discover usernames, passwords, and unspecified othe
MeetingTime in Cisco Unified MeetingPlace 6 before MR5, and possibly 5, allows remote attackers to discover usernames, passwords, and unspecified other data from the user database via a modified authentication sequence to the Audio Server, aka Bug ID CSCsv76935.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2010-01-28
Published