3.5
CVSSv2

CVE-2013-6964

Published: 14/12/2013 Updated: 29/11/2017
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

A vulnerability in the site access control implementation of Cisco WebEx Business Suite could allow an authenticated, remote malicious user to inject content from the attacker-controlled WebEx site into another WebEx site. The vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by using a crafted URL to inject content from the attacker-controlled WebEx site into another WebEx site. Cisco has confirmed the vulnerability in a security notice; however, software updates are not available. To exploit this vulnerability, an attacker must authenticate to the targeted device. This access requirement limits the possibility of a successful exploit. Cisco indicates through the CVSS score that functional exploit code exists; however, the code is not known to be publicly available.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cisco webex meeting center -

Vendor Advisories

A vulnerability in the site access control implementation of Cisco WebEx Business Suite could allow an authenticated, remote attacker to inject content from the attacker-controlled WebEx site into another WebEx site The vulnerability is due to insufficient validation of user-supplied input An attacker could exploit this vulnerability by using a ...