Release date:
Updated on:
Affected Systems:
Cisco Telepresence Recording Server 1.6.1
Cisco Telepresence Recording Server 1.6
Cisco CTMS: Cisco CTMS 1.6
Cisco CTMS: Cisco CTMS 1.5
Cisco CTMS: Cisco CTMS 1.1
Cisco CTMS: Cisco CTMS 1.0
Unaffected system:
Cisco Telepresence Recording Server 1.6.2
Cisco CTMS: Cisco CTMS 1.7
Description:
--------------------------------------------------------------------------------
Bugtraq id: 46516
Cve id: CVE-2011-0385
Cisco TelePresence is a Cisco TelePresence solution that collaborates with colleagues, partners, and customers around the world in a timely manner.
Cisco TelePresence has multiple Implementation Vulnerabilities. Attackers can exploit these vulnerabilities to upload arbitrary files and execute arbitrary code.
This vulnerability occurs because the application fails to properly filter user input.
<**>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Cisco
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.cisco.com/warp/public/707/advisory.html