Cisco TelePresence Recording Server Web Interface Remote Command Injection Vulnerability
20 Jul. 2012
Summary
Cisco TelePresence Recording Server is prone to a remote command-injection vulnerability.
Credit:
The original article can be found at: http://www.securityfocus.com/bid/54385
The information has been provided by miaubiz and Alexey Samsonov of Google /B>.
Vulnerable Systems:
*Cisco Telepresence Recording Server 1.7.2 and prior
Successful exploits will result in the execution of arbitrary attacker-supplied commands in the context of the root user. This may facilitate a complete compromise.This issue is being tracked by Cisco bug ID CSCti21830
Vendor Status:
Vendor as issued an updated vulnerability.