CVE-2011-4232
published 2012-05-03CVE-2011-4232: The web server in Cisco Unified MeetingPlace 6.1 and 8.5 produces different responses for directory queries depending on whether the directory exists, which…
PriorityP426medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
1.17%
64.0th percentile
The web server in Cisco Unified MeetingPlace 6.1 and 8.5 produces different responses for directory queries depending on whether the directory exists, which allows remote attackers to enumerate directory names via a series of queries, aka Bug ID CSCtt94070.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_meetingplace | — | — |
| cisco | unified_meetingplace | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_cisco5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Unified MeetingPlace Directory Enumeration Information Disclosure Vulnerability
vendor_cisco·2012-05-11·CVSS 5.0
CVE-2011-4232 [MEDIUM] CWE-200 Cisco Unified MeetingPlace Directory Enumeration Information Disclosure Vulnerability
Cisco Unified MeetingPlace Directory Enumeration Information Disclosure Vulnerability
Cisco Unified MeetingPlace software contains a vulnerability that could allow an unauthenticated, remote attacker to access sensitive information on a targeted system.
The vulnerability is due to an unspecified error in the affected software that could allow an attacker to enumerate existing folders via directory transversal sequences. An unauthenticated, remote attacker could exploit this vulnerability to access sensitive information on the system. The attacker could use this information to launch further attacks.
Cisco has confirmed this vulnerability and released software updates.
To exploit this vulnerability, an attacker would need to access trusted, internal networks. This access requirement decr
GHSA
GHSA-hqm4-73mw-3x29: The web server in Cisco Unified MeetingPlace 6
ghsa_unreviewed·2022-05-17
CVE-2011-4232 [MEDIUM] CWE-200 GHSA-hqm4-73mw-3x29: The web server in Cisco Unified MeetingPlace 6
The web server in Cisco Unified MeetingPlace 6.1 and 8.5 produces different responses for directory queries depending on whether the directory exists, which allows remote attackers to enumerate directory names via a series of queries, aka Bug ID CSCtt94070.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2012-05-03
Published