{"$ref":"https://www.cert.ssi.gouv.fr/openapi.json","affected_systems":[{"description":"Cisco Unified MeetingPlace Web Conferencing 8.5","product":{"name":"N/A","vendor":{"name":"Cisco","scada":false}}},{"description":"Cisco Unified MeetingPlace Web Conferencing 8.0","product":{"name":"N/A","vendor":{"name":"Cisco","scada":false}}},{"description":"Cisco Unified MeetingPlace Web Conferencing 7.0","product":{"name":"N/A","vendor":{"name":"Cisco","scada":false}}},{"description":"Cisco Unified MeetingPlace Web Conferencing 7.1","product":{"name":"N/A","vendor":{"name":"Cisco","scada":false}}},{"description":"Cisco Unified MeetingPlace Web Conferencing 6.0","product":{"name":"N/A","vendor":{"name":"Cisco","scada":false}}}],"affected_systems_content":null,"content":"## Solution\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l'\u00e9diteur pour l'obtention des\ncorrectifs (cf. section Documentation).\n","cves":[{"name":"CVE-2012-5416","url":"https://www.cve.org/CVERecord?id=CVE-2012-5416"},{"name":"CVE-2012-0337","url":"https://www.cve.org/CVERecord?id=CVE-2012-0337"}],"links":[],"reference":"CERTA-2012-AVI-615","revisions":[{"description":"version initiale.","revision_date":"2012-11-02T00:00:00.000000"}],"risks":[{"description":"D\u00e9ni de service \u00e0 distance"},{"description":"Injection de code indirecte \u00e0 distance"}],"summary":"De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 corrig\u00e9es dans <span\nclass=\"textit\">Cisco Unified MeetingPlace Web Conferencing</span>. La\nplus critique permet \u00e0 un attaquant non authentifi\u00e9 de provoquer une\ninjection de code indirecte \u00e0 distance (injection SQL) \u00e0 l'aide d'une\nrequ\u00eate HTTP POST.\n","title":"Multiples vuln\u00e9rabilit\u00e9s dans Cisco Unified MeetingPlace Web Conferencing","vendor_advisories":[{"published_at":null,"title":"Bulletin de s\u00e9curit\u00e9 CISCO CSCua66341 du 31 octobre 2012","url":"http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20121031-mp"}]}
