CVE-2015-0702
CVE-2015-0702 is a critical-severity vulnerability in Cisco Unified Meetingplace with a CVSS 2.0 base score of 9.0. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-20.
Key facts
- Severity: Critical (CVSS 2.0 base score 9.0)
- EPSS exploit prediction: 3% (86th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-20
- Affected product: Cisco Unified Meetingplace
- Published:
- Last modified:
Description
Unrestricted file upload vulnerability in the Custom Prompts upload implementation in Cisco Unified MeetingPlace 8.6(1.9) allows remote authenticated users to execute arbitrary code by using the languageShortName parameter to upload a file that provides shell access, aka Bug ID CSCus95712.
Frequently asked questions
- What is CVE-2015-0702?
- Unrestricted file upload vulnerability in the Custom Prompts upload implementation in Cisco Unified MeetingPlace 8.6(1.9) allows remote authenticated users to execute arbitrary code by using the languageShortName parameter to upload a file that provides shell access, aka Bug ID CSCus95712.
- How severe is CVE-2015-0702?
- CVE-2015-0702 has a CVSS 2.0 base score of 9.0, rated critical severity.
- Is CVE-2015-0702 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 3% (86th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2015-0702?
- CVE-2015-0702 affects Cisco Unified Meetingplace. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2015-0702?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its critical severity, prioritise patching exposed systems.
- When was CVE-2015-0702 published?
- CVE-2015-0702 was published on 2015-04-21 and last updated on 2026-06-17.
References
- http://tools.cisco.com/security/center/viewAlert.x?alertId=38455
- http://www.securitytracker.com/id/1032165
Affected products (1)
- cpe:2.3:a:cisco:unified_meetingplace:8.6\(1.9\):*:*:*:*:*:*:*
More vulnerabilities in Cisco Unified Meetingplace
- CVE-2010-0140 — Critical (CVSS 10.0): Multiple unspecified vulnerabilities in the web server in Cisco Unified MeetingPlace 7 before 7.0(2.3) hotfix 5F, 6…
- CVE-2010-0139 — Critical (CVSS 9.0): Cisco Unified MeetingPlace 7 before 7.0(2.3) hotfix 5F, 6 before 6.0.639.2, and possibly 5 does not properly validate…
- CVE-2010-0142 — High (CVSS 8.5): MeetingTime in Cisco Unified MeetingPlace 6 before MR5, and possibly 5, allows remote authenticated users to gain…
- CVE-2012-5416 — High (CVSS 7.8): Buffer overflow in Cisco Unified MeetingPlace Web Conferencing before 7.1MR1 Patch 1, 8.0 before 8.0MR1 Patch 1, and…
- CVE-2013-1168 — High (CVSS 7.6): The web server in Cisco Unified MeetingPlace Application Server 7.x before 7.1MR1 Patch 2, 8.0 before 8.0MR1 Patch 1,…
- CVE-2015-0705 — Medium (CVSS 6.8): Cross-site request forgery (CSRF) vulnerability in the SOAP API endpoints of the web-services directory in Cisco…
All CVEs affecting Cisco Unified Meetingplace →
Other CWE-20 (Improper Input Validation) vulnerabilities
- CVE-2026-48056 — Critical (CVSS 10.0): Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0…
- CVE-2026-33267 — Critical (CVSS 10.0): Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.2.0…
- CVE-2026-47668 — Critical (CVSS 10.0): DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's JSON script runner (`POST…
- CVE-2026-16117 — Critical (CVSS 10.0): Impact: @fastify/http-proxy versions up to and including 11.5.0 fail to rewrite the request prefix when the prefix…
- CVE-2026-48316 — Critical (CVSS 10.0): ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could…
- CVE-2026-48281 — Critical (CVSS 10.0): ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could…
Browse all CWE-20 (Improper Input Validation) vulnerabilities →