5
CVSSv2

CVE-2014-3301

Published: 26/07/2014 Updated: 29/08/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The ProfileAction controller in Cisco WebEx Meetings Server (CWMS) 1.5(.1.131) and previous versions allows remote malicious users to obtain sensitive information by reading stack traces in returned messages, aka Bug ID CSCuj81700.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco webex meetings server 1.5

cisco webex meetings server

cisco webex meetings server 1.5\\(.1.6\\)

Vendor Advisories

A vulnerability in the ProfileAction controller of Cisco WebEx Meetings Server (CWMS) could allow an unauthenticated, remote attacker to view sensitive information The vulnerability is due to improper sanitization of returned messages An attacker could exploit this vulnerability by submitting crafted URL requests to a vulnerable device Cisco ...