CVE-2015-4208

Cisco WebEx Meeting Center does not properly restrict the content of URLs in GET requests, which allows remote attackers to obtain sensitive information or conduct SQL injection attacks via vectors involving read access to a request, aka Bug ID CSCup88398.
References
Link Resource
http://tools.cisco.com/security/center/viewAlert.x?alertId=39458 Vendor Advisory
http://www.securityfocus.com/bid/75361 Third Party Advisory VDB Entry
http://www.securitytracker.com/id/1032705 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:cisco:webex_meeting_center:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2015-06-24 10:59

Updated : 2024-02-04 18:53


NVD link : CVE-2015-4208

Mitre link : CVE-2015-4208

CVE.ORG link : CVE-2015-4208


JSON object : View

Products Affected

cisco

  • webex_meeting_center
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')