5
CVSSv2

CVE-2014-3304

Published: 28/07/2014 Updated: 29/08/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The OutlookAction Class in Cisco WebEx Meetings Server allows remote malicious users to enumerate user accounts by entering crafted URLs and examining the returned messages, aka Bug ID CSCuj81722.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco webex meetings server -

Vendor Advisories

A vulnerability in the OutlookAction Class of Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to enumerate valid user accounts The vulnerability is due to improper sanitization of a returned message An attacker could exploit this vulnerability by sending crafted URL requests to a vulnerable device Cisco has confirm ...