5.8
CVSSv2

CVE-2014-3302

Published: 01/08/2014 Updated: 29/08/2017
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N

Vulnerability Summary

user.php in Cisco WebEx Meetings Server 1.5(.1.131) and previous versions does not properly implement the token timer for authenticated encryption, which allows remote malicious users to obtain sensitive information via a crafted URL, aka Bug ID CSCuj81708.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco webex meetings server 1.5

cisco webex meetings server

cisco webex meetings server 1.5\\(.1.6\\)

Vendor Advisories

A vulnerability in the userphp script of Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to view sensitive information The vulnerability is due to an invalid token timer An attacker could exploit this vulnerability by submitting crafted URL requests to a vulnerable device Cisco has confirmed the vulnerability in a ...