CVE-2011-4232
Published May 3, 2012
Last updated 12 years ago
Overview
- Description
- The web server in Cisco Unified MeetingPlace 6.1 and 8.5 produces different responses for directory queries depending on whether the directory exists, which allows remote attackers to enumerate directory names via a series of queries, aka Bug ID CSCtt94070.
- Source
- ykramarz@cisco.com
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 5
- Impact score
- 2.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:N/A:N
Weaknesses
- nvd@nist.gov
- CWE-200
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:cisco:unified_meetingplace:6.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1EBAE375-3CD0-4749-B446-A79B7C08AE9F" }, { "criteria": "cpe:2.3:a:cisco:unified_meetingplace:8.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5FF3D6AE-38E4-40C7-AD5D-C7DA67AB9DCC" } ], "operator": "OR" } ] } ]