Back to search
CVE-2013-1168
Published: Apr 11, 2013
Modified: Sep 16, 2024
PUBLISHED
Description
The web server in Cisco Unified MeetingPlace Application Server 7.x before 7.1MR1 Patch 2, 8.0 before 8.0MR1 Patch 1, and 8.5 before 8.5MR3 Patch 1 does not invalidate a session upon a logout action, which makes it easier for remote attackers to hijack sessions by leveraging knowledge of a session cookie, aka Bug ID CSCuc64885.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
20130410 Multiple Vulnerabilities in Cisco Unified MeetingPlace Solution
vendor-advisory
x_refsource_CISCO
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now