CVE-2011-2585
Description
Cisco Show and Share 5.2(2) and earlier allow authenticated users with video upload privileges to upload and execute arbitrary code.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Cisco Show and Share 5.2(2) and earlier allow authenticated users with video upload privileges to upload and execute arbitrary code.
Vulnerability
Cisco Show and Share versions 5(2), 5.2(1), and 5.2(2) before 5.2(2.1) contain a vulnerability that allows remote authenticated users to upload and execute arbitrary code. The issue is identified as Bug ID CSCto69857 and is described in Cisco Security Advisory cisco-sa-20111019-sns [1]. The vulnerability exists in the video upload functionality, which does not properly validate uploaded files, enabling arbitrary code execution.
Exploitation
An attacker must have valid credentials for the Cisco Show and Share application and must possess video upload privileges. With these privileges, the attacker can upload a crafted file containing malicious code, which is then executed on the server. No user interaction beyond the attacker's own actions is required, and the attacker can perform this remotely over the network [1].
Impact
Successful exploitation allows the attacker to execute arbitrary code on the underlying server. This can lead to complete compromise of the application and the host system, including unauthorized access to data, modification of content, and potential denial of service. The privilege level achieved is that of the application process, which typically runs with high privileges [1].
Mitigation
Cisco has released fixed version 5.2(2.1) to address this vulnerability. Users are advised to upgrade to this version or later. The advisory also notes that version 5.2(3) does not support certain MCS Server Appliances, so administrators should use 5.2(2.1) or later as recommended. No workarounds are provided in the reference [1].
AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
4cpe:2.3:a:cisco:show_and_share:*:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:cisco:show_and_share:*:*:*:*:*:*:*:*range: <=5.2\(2\)
- cpe:2.3:a:cisco:show_and_share:5\(2\):*:*:*:*:*:*:*
- cpe:2.3:a:cisco:show_and_share:5.2\(1\):*:*:*:*:*:*:*
- (no CPE)range: <5.2(2.1)
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.