CVE-2011-4232

The web server in Cisco Unified MeetingPlace 6.1 and 8.5 produces different responses for directory queries depending on whether the directory exists, which allows remote attackers to enumerate directory names via a series of queries, aka Bug ID CSCtt94070.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:cisco:unified_meetingplace:6.1:*:*:*:*:*:*:*
cpe:2.3:a:cisco:unified_meetingplace:8.5:*:*:*:*:*:*:*

History

21 Nov 2024, 01:32

Type Values Removed Values Added
References () http://www.cisco.com/en/US/docs/voice_ip_comm/meetingplace/6_1/release_notes/mp61_rn.pdf - () http://www.cisco.com/en/US/docs/voice_ip_comm/meetingplace/6_1/release_notes/mp61_rn.pdf -
References () http://www.securityfocus.com/bid/53432 - () http://www.securityfocus.com/bid/53432 -

Information

Published : 2012-05-03 10:11

Updated : 2024-11-21 01:32


NVD link : CVE-2011-4232

Mitre link : CVE-2011-4232

CVE.ORG link : CVE-2011-4232


JSON object : View

Products Affected

cisco

  • unified_meetingplace
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor