The web server in Cisco Unified MeetingPlace 6.1 and 8.5 produces different responses for directory queries depending on whether the directory exists, which allows remote attackers to enumerate directory names via a series of queries, aka Bug ID CSCtt94070.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 01:32
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.cisco.com/en/US/docs/voice_ip_comm/meetingplace/6_1/release_notes/mp61_rn.pdf - | |
References | () http://www.securityfocus.com/bid/53432 - |
Information
Published : 2012-05-03 10:11
Updated : 2024-11-21 01:32
NVD link : CVE-2011-4232
Mitre link : CVE-2011-4232
CVE.ORG link : CVE-2011-4232
JSON object : View
Products Affected
cisco
- unified_meetingplace
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor