7.5
CVSSv2

CVE-2015-4208

Published: 24/06/2015 Updated: 28/12/2016
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cisco WebEx Meeting Center does not properly restrict the content of URLs in GET requests, which allows remote malicious users to obtain sensitive information or conduct SQL injection attacks via vectors involving read access to a request, aka Bug ID CSCup88398.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco webex meeting center -

Vendor Advisories

A vulnerability in Cisco WebEx Meeting Center could allow an unauthenticated, remote attacker to view sensitive information that is transmitted in GET parameters or perform SQL injection The vulnerability is due to the inclusion of sensitive information in the URL as GET parameters An attacker could exploit this vulnerability by viewing applica ...