Vulnerability Description
Cisco Unified MeetingPlace 7 before 7.0(2.3) hotfix 5F, 6 before 6.0.639.2, and possibly 5 does not properly validate SQL commands, which allows remote attackers to create, modify, or delete data in a database via unspecified vectors, aka Bug ID CSCtc39691.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Unified Meetingplace | 5 |
Related Weaknesses (CWE)
References
- http://www.cisco.com/en/US/products/products_security_advisory09186a0080b1490b.sPatchVendor Advisory
- http://www.securityfocus.com/bid/37965
- http://www.cisco.com/en/US/products/products_security_advisory09186a0080b1490b.sPatchVendor Advisory
- http://www.securityfocus.com/bid/37965
FAQ
What is CVE-2010-0139?
CVE-2010-0139 is a vulnerability with a CVSS score of 9.0 (HIGH). Cisco Unified MeetingPlace 7 before 7.0(2.3) hotfix 5F, 6 before 6.0.639.2, and possibly 5 does not properly validate SQL commands, which allows remote attackers to create, modify, or delete data in a...
How severe is CVE-2010-0139?
CVE-2010-0139 has been rated HIGH with a CVSS base score of 9.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2010-0139?
Check the references section above for vendor advisories and patch information. Affected products include: Cisco Unified Meetingplace.