PT-2015-4823 · Cisco · Cisco Unified Meetingplace
Published
2015-04-21
·
Updated
2017-01-06
·
CVE-2015-0702
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco Unified MeetingPlace version 8.6(1.9)
Description
The issue is related to an unrestricted file upload vulnerability in the Custom Prompts upload implementation. This allows remote authenticated users to execute arbitrary code by uploading a file that provides shell access, using the
languageShortName parameter.Recommendations
For Cisco Unified MeetingPlace version 8.6(1.9), consider restricting access to the Custom Prompts upload feature until a fix is available, and avoid using the
languageShortName parameter to upload files. At the moment, there is no information about a newer version that contains a fix for this vulnerability.RCE
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Unified Meetingplace