CVE-2015-0702

Unrestricted file upload vulnerability in the Custom Prompts upload implementation in Cisco Unified MeetingPlace 8.6(1.9) allows remote authenticated users to execute arbitrary code by using the languageShortName parameter to upload a file that provides shell access, aka Bug ID CSCus95712.

SeverityHIGH
CVSS9.0
EPSS1.68% EPSS medium
CWECWE-20
KEV
Published
Modified

Public Affected Products

Product Advisory Evidence
Cisco Unified MeetingPlace Cisco-SA-20150420-CVE-2015-0702 Cisco CSAF ยท structured affected