Cisco WebEx Business Suite Site Access Control Bypass Vulnerability

Related Vulnerabilities: CVE-2013-6964  

A vulnerability in the site access control implementation of Cisco WebEx Business Suite could allow an authenticated, remote attacker to inject content from the attacker-controlled WebEx site into another WebEx site. The vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by using a crafted URL to inject content from the attacker-controlled WebEx site into another WebEx site. Cisco has confirmed the vulnerability in a security notice; however, software updates are not available. To exploit this vulnerability, an attacker must authenticate to the targeted device. This access requirement limits the possibility of a successful exploit. Cisco indicates through the CVSS score that functional exploit code exists; however, the code is not known to be publicly available.