cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
504
Views
0
Helpful
1
Replies

Closing remote file download hole in MeetingPlace 2.1.1.2?

cjansen171
Level 1
Level 1

Hi, I'm trying to find out how to address the issue that you can browse to /public/tutorial?video=/../..//../..//../..//../..//../..//etc/passwd and download the passwd and similarly other files on the filesystem on MeetingPlace without any sort of authentication. Has there been a patch or some way to address this vulnerability?

Thanks!

1 Reply 1

Brad Martin
Level 3
Level 3

That's amazing. We shut down our system. Do you know if Cisco has documented this anywhere?