ID

VAR-201205-0332


CVE

CVE-2011-4232


TITLE

Cisco Unified MeetingPlace of Web Server directory enumeration vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2012-002229

DESCRIPTION

The web server in Cisco Unified MeetingPlace 6.1 and 8.5 produces different responses for directory queries depending on whether the directory exists, which allows remote attackers to enumerate directory names via a series of queries, aka Bug ID CSCtt94070. Cisco Unified MeetingPlace is prone to a directory enumeration weakness and multiple cross-site scripting vulnerabilities. A remote attacker can exploit the directory-enumeration weakness to enumerate existing folders; other attacks are also possible. Attackers can also execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This will allow attackers to steal cookie-based authentication credentials and launch other attacks. Cisco Unified MeetingPlace is a set of multimedia conferencing solutions of Cisco (Cisco). This solution provides a user environment that integrates voice, video and Web conferencing

Trust: 1.98

sources: NVD: CVE-2011-4232 // JVNDB: JVNDB-2012-002229 // BID: 53432 // VULHUB: VHN-52177

AFFECTED PRODUCTS

vendor:ciscomodel:unified meetingplacescope:eqversion:6.1

Trust: 2.4

vendor:ciscomodel:unified meetingplacescope:eqversion:8.5

Trust: 2.4

vendor:ciscomodel:unified meetingplacescope:eqversion:6.0.639.3

Trust: 0.3

vendor:ciscomodel:unified meetingplacescope:eqversion:6.0.639.2

Trust: 0.3

vendor:ciscomodel:unified meetingplacescope:eqversion:6

Trust: 0.3

vendor:ciscomodel:unified meetingplacescope:neversion:6.1.1.4

Trust: 0.3

sources: BID: 53432 // JVNDB: JVNDB-2012-002229 // CNNVD: CNNVD-201205-070 // NVD: CVE-2011-4232

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2011-4232
value: MEDIUM

Trust: 1.0

NVD: CVE-2011-4232
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201205-070
value: MEDIUM

Trust: 0.6

VULHUB: VHN-52177
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2011-4232
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-52177
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-52177 // JVNDB: JVNDB-2012-002229 // CNNVD: CNNVD-201205-070 // NVD: CVE-2011-4232

PROBLEMTYPE DATA

problemtype:CWE-200

Trust: 1.9

sources: VULHUB: VHN-52177 // JVNDB: JVNDB-2012-002229 // NVD: CVE-2011-4232

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201205-070

TYPE

information disclosure

Trust: 0.6

sources: CNNVD: CNNVD-201205-070

CONFIGURATIONS

sources: JVNDB: JVNDB-2012-002229

PATCH

title:Release Notes for Cisco Unified MeetingPlace Release 6.1url:http://www.cisco.com/en/US/docs/voice_ip_comm/meetingplace/6_1/release_notes/mp61_rn.pdf

Trust: 0.8

sources: JVNDB: JVNDB-2012-002229

EXTERNAL IDS

db:NVDid:CVE-2011-4232

Trust: 2.8

db:BIDid:53432

Trust: 1.4

db:JVNDBid:JVNDB-2012-002229

Trust: 0.8

db:NSFOCUSid:19588

Trust: 0.6

db:CNNVDid:CNNVD-201205-070

Trust: 0.6

db:VULHUBid:VHN-52177

Trust: 0.1

sources: VULHUB: VHN-52177 // BID: 53432 // JVNDB: JVNDB-2012-002229 // CNNVD: CNNVD-201205-070 // NVD: CVE-2011-4232

REFERENCES

url:http://www.cisco.com/en/us/docs/voice_ip_comm/meetingplace/6_1/release_notes/mp61_rn.pdf

Trust: 2.0

url:http://www.securityfocus.com/bid/53432

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2011-4232

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2011-4232

Trust: 0.8

url:http://www.nsfocus.net/vulndb/19588

Trust: 0.6

url:http://www.cisco.com/en/us/products/sw/ps5664/ps5669/index.html

Trust: 0.3

sources: VULHUB: VHN-52177 // BID: 53432 // JVNDB: JVNDB-2012-002229 // CNNVD: CNNVD-201205-070 // NVD: CVE-2011-4232

CREDITS

Cisco

Trust: 0.3

sources: BID: 53432

SOURCES

db:VULHUBid:VHN-52177
db:BIDid:53432
db:JVNDBid:JVNDB-2012-002229
db:CNNVDid:CNNVD-201205-070
db:NVDid:CVE-2011-4232

LAST UPDATE DATE

2025-04-11T23:08:51.134000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-52177date:2012-05-30T00:00:00
db:BIDid:53432date:2012-05-09T00:00:00
db:JVNDBid:JVNDB-2012-002229date:2012-05-08T00:00:00
db:CNNVDid:CNNVD-201205-070date:2012-05-04T00:00:00
db:NVDid:CVE-2011-4232date:2025-04-11T00:51:21.963

SOURCES RELEASE DATE

db:VULHUBid:VHN-52177date:2012-05-03T00:00:00
db:BIDid:53432date:2012-05-09T00:00:00
db:JVNDBid:JVNDB-2012-002229date:2012-05-08T00:00:00
db:CNNVDid:CNNVD-201205-070date:2012-05-04T00:00:00
db:NVDid:CVE-2011-4232date:2012-05-03T10:11:39.733