Update: Another Advisory from Cisco reporting a SQL injection and buffer overrun vulnerability in Cisco Unified MeetingPlace Web Conferencing product. SQL Injection Vulnerability may allow an unauthenticated, remote attacker to send Structured Query Language (SQL) commands to manipulate the MeetingPlace database stores information about server configuration, meetings, and users. These commands may be used to create, delete, or alter some of the information in the Cisco Unified MeetingPlace Web Conferencing database.
Affected versions are Prior to 7.0 ,7.0 ,7.1 ,8.0 and 8.5. Cisco has released free software updates that address the vulnerabilities described in this advisory.