Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The password-change feature in Cisco Unified MeetingPlace Web Conferencing before 8.5(5) MR3 and 8.6 before 8.6(2) does not check the session ID or require entry of the current password, which allows remote attackers to reset arbitrary passwords via a crafted HTTP request, aka Bug ID CSCuu51839.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Cisco Unified MeetingPlace Web Conferencing 信任管理漏洞
Vulnerability Description
Cisco Unified MeetingPlace Web Conferencing是美国思科(Cisco)公司的一个Cisco Unified MeetingPlace多媒体会议解决方案中的核心组件。 Cisco Unified MeetingPlace Web Conferencing 8.5(5) MR3之前8.5版本和8.6(2)之前8.6版本的password-change功能中存在安全漏洞,该漏洞源于程序在处理password-change请求时没有要求输入当前密码;程序中的HTTP会话功能
CVSS Information
N/A
Vulnerability Type
N/A