CVE-2012-0337
published 2012-05-02CVE-2012-0337: SQL injection vulnerability in the web component in Cisco Unified MeetingPlace 7.1 allows remote authenticated users to execute arbitrary SQL commands via…
PriorityP336medium6.5CVSS 2.0
AVNACLAuSCPIPAP
EPSS
0.97%
58.0th percentile
SQL injection vulnerability in the web component in Cisco Unified MeetingPlace 7.1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCtx08939.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_meetingplace | — | — |
| cisco | unified_meetingplace_web_conferencing | — | — |
CVSS provenance
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_cisco8.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-j2pp-2c3q-43g3: SQL injection vulnerability in the web component in Cisco Unified MeetingPlace 7
ghsa_unreviewed·2022-05-04
CVE-2012-0337 [MEDIUM] CWE-89 GHSA-j2pp-2c3q-43g3: SQL injection vulnerability in the web component in Cisco Unified MeetingPlace 7
SQL injection vulnerability in the web component in Cisco Unified MeetingPlace 7.1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCtx08939.
Cisco
Multiple Vulnerabilities in Cisco Unified MeetingPlace Web Conferencing
vendor_cisco·2012-10-31·CVSS 8.5
CVE-2012-0337 [HIGH] CWE-119 Multiple Vulnerabilities in Cisco Unified MeetingPlace Web Conferencing
Multiple Vulnerabilities in Cisco Unified MeetingPlace Web Conferencing
Cisco Unified MeetingPlace Web Conferencing is affected by two vulnerabilities:
Cisco Unified MeetingPlace Web Conferencing SQL Injection Vulnerability
Cisco Unified MeetingPlace Web Conferencing Buffer Overrun Vulnerability
Exploitation of the Cisco Unified MeetingPlace Web Conferencing SQL Injection Vulnerability may allow an unauthenticated, remote attacker to send Structured Query Language (SQL) commands to manipulate the MeetingPlace database stores information about server
configuration, meetings, and users. These commands may be used to create,
delete, or alter some of the information in the Cisco Unified
MeetingPlace Web Conferencing database.
Exploitation of the Cisco Unified MeetingPlace Web Conferencing
Cisco
Cisco Unified MeetingPlace Web Conferencing SQL Injection Vulnerability
vendor_cisco·2012-10-31·CVSS 6.5
CVE-2012-0337 [MEDIUM] CWE-89 Cisco Unified MeetingPlace Web Conferencing SQL Injection Vulnerability
Cisco Unified MeetingPlace Web Conferencing SQL Injection Vulnerability
Cisco Unified MeetingPlace Web Conferencing contains a vulnerability that could allow an unauthenticated, remote attacker to conduct a SQL injection attack.
The vulnerability is due to insufficient validation of user-supplied input to an HTTP POST method. An unauthenticated, remote attacker could exploit this vulnerability by sending HTTP POST requests that contain crafted SQL statements to the targeted system. A successful exploit could allow the attacker to modify or delete data from the Web Conferencing database.
Cisco has confirmed these vulnerabilities in a security advisory and released updated software.
To exploit the vulnerability, the attacker must send malicious requests to the targeted system, likely re
Cisco
Cisco Unified MeetingPlace SQL Injection Vulnerability
vendor_cisco·2012-05-10·CVSS 6.5
CVE-2012-0337 [MEDIUM] CWE-89 Cisco Unified MeetingPlace SQL Injection Vulnerability
Cisco Unified MeetingPlace SQL Injection Vulnerability
Cisco Unified MeetingPlace contains a vulnerability that could allow an authenticated, remote attacker to execute arbitrary SQL code on a targeted system.
The vulnerability is due to improper validation of user-supplied input to the web-based application interface. An authenticated, remote attacker could exploit this vulnerability by sending malicious requests to the system. If successful, the attacker could execute arbitrary SQL code against the database underlying the affected application.
Cisco has confirmed this vulnerability in a bug report and has released updated software.
To exploit this vulnerability, the attacker would need to authenticate to the targeted device. To achieve this objective, the attacker may need access to t
Cisco
Multiple Vulnerabilities in Cisco Unified MeetingPlace Web Conferencing
vendor_cisco
CVE-2012-0337 Multiple Vulnerabilities in Cisco Unified MeetingPlace Web Conferencing
CVE-2012-0337: Multiple Vulnerabilities in Cisco Unified MeetingPlace Web Conferencing
Cisco Unified MeetingPlace Web Conferencing is affected by two vulnerabilities: Cisco Unified MeetingPlace Web Conferencing SQL Injection Vulnerability Cisco Unified MeetingPlace Web Conferencing Buffer Overrun Vulnerability Exploitation of the Cisco Unified MeetingPlace Web Conferencing SQL Injection Vulnerability may allow an unauthenticated, remote attacker to send Structured Query Language (SQL) commands to manipulate the MeetingPlace database stores information about server configuration, meetings, and users. These commands may be used to create, delete, or alter some of the information in the Cisco Unified MeetingPlace Web Conferencing database. Exploitation of the Cisco Unified MeetingPlace Web Co
No detection rules found.
No public exploits indexed.
2012-05-02
Published