The registration component in Cisco WebEx Training Center provides the training-session URL before payment is completed, which allows remote attackers to bypass intended access restrictions and join an audio conference by entering credential fields from this URL, aka Bug ID CSCul57111.
References
Link | Resource |
---|---|
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-6709 | Vendor Advisory |
http://tools.cisco.com/security/center/viewAlert.x?alertId=32153 | Vendor Advisory |
http://www.securitytracker.com/id/1029492 | Third Party Advisory VDB Entry |
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-6709 | Vendor Advisory |
http://tools.cisco.com/security/center/viewAlert.x?alertId=32153 | Vendor Advisory |
http://www.securitytracker.com/id/1029492 | Third Party Advisory VDB Entry |
Configurations
History
21 Nov 2024, 01:59
Type | Values Removed | Values Added |
---|---|---|
References | () http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-6709 - Vendor Advisory | |
References | () http://tools.cisco.com/security/center/viewAlert.x?alertId=32153 - Vendor Advisory | |
References | () http://www.securitytracker.com/id/1029492 - Third Party Advisory, VDB Entry |
Information
Published : 2013-12-14 22:55
Updated : 2024-11-21 01:59
NVD link : CVE-2013-6709
Mitre link : CVE-2013-6709
CVE.ORG link : CVE-2013-6709
JSON object : View
Products Affected
cisco
- webex_training_center
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor