5
CVSSv2

CVE-2014-3286

Published: 08/06/2014 Updated: 07/09/2016
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The web framework in Cisco WebEx Meeting Server does not properly restrict the content of reply messages, which allows remote malicious users to obtain sensitive information via a crafted URL, aka Bug IDs CSCuj81685, CSCuj81688, CSCuj81665, CSCuj81744, and CSCuj81661.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco webex meetings server -

Vendor Advisories

A vulnerability in the web framework of Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to enumerate valid user accounts The vulnerability is due to improper sanitization of a returned message An attacker could exploit this vulnerability by sending crafted URL requests to a vulnerable device Cisco has confirmed the ...