5
CVSSv2

CVE-2013-5489

Published: 13/09/2013 Updated: 29/08/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The gadget implementation in Cisco SocialMiner does not properly restrict the content of GET requests, which allows remote malicious users to obtain sensitive information by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history, aka Bug ID CSCuh74125.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco socialminer -

Vendor Advisories

A vulnerability in some of the gadgets of Cisco SocialMiner could allow an unauthenticated, remote attacker to collect sensitive information The vulnerability is due to sensitive information being transmitted within a gadget's GET request An attacker could exploit this vulnerability by capturing the GET request of a SocialMiner gadget An exploi ...