CVE-2015-4208

Cisco WebEx Meeting Center does not properly restrict the content of URLs in GET requests, which allows remote attackers to obtain sensitive information or conduct SQL injection attacks via vectors involving read access to a request, aka Bug ID CSCup88398.
Configurations

Configuration 1 (hide)

cpe:2.3:a:cisco:webex_meeting_center:-:*:*:*:*:*:*:*

History

21 Nov 2024, 02:30

Type Values Removed Values Added
References () http://tools.cisco.com/security/center/viewAlert.x?alertId=39458 - Vendor Advisory () http://tools.cisco.com/security/center/viewAlert.x?alertId=39458 - Vendor Advisory
References () http://www.securityfocus.com/bid/75361 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/75361 - Third Party Advisory, VDB Entry
References () http://www.securitytracker.com/id/1032705 - Third Party Advisory, VDB Entry () http://www.securitytracker.com/id/1032705 - Third Party Advisory, VDB Entry

Information

Published : 2015-06-24 10:59

Updated : 2024-11-21 02:30


NVD link : CVE-2015-4208

Mitre link : CVE-2015-4208

CVE.ORG link : CVE-2015-4208


JSON object : View

Products Affected

cisco

  • webex_meeting_center
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

CWE-200

Exposure of Sensitive Information to an Unauthorized Actor