VendorsCiscowebex_meetings_server1.5\(.1.6\)
Vulnerabilities

Cisco Webex Meetings Server 1.5\(.1.6\)

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2014-3305
Cross-site request forgery (CSRF) vulnerability in the web framework in Cisco WebEx Meetings Server 1.5(.1.131) and earlier allows remote attackers to hijack the authentication of unspecified victims via unknown vectors, aka Bug ID CSCuj81735.
Published 2014-07-26 · Modified
6.8EPSS 0.013
CVE-2014-3302
user.php in Cisco WebEx Meetings Server 1.5(.1.131) and earlier does not properly implement the token timer for authenticated encryption, which allows remote attackers to obtain sensitive information via a crafted URL, aka Bug ID CSCuj81708.
Published 2014-08-01 · Modified
5.8EPSS 0.010
CVE-2014-3301
The ProfileAction controller in Cisco WebEx Meetings Server (CWMS) 1.5(.1.131) and earlier allows remote attackers to obtain sensitive information by reading stack traces in returned messages, aka Bug ID CSCuj81700.
Published 2014-07-26 · Modified
5.0EPSS 0.018
CVE-2014-3296
The XML programmatic interface (XML PI) in Cisco WebEx Meeting Server 1.5(.1.131) and earlier allows remote authenticated users to obtain sensitive meeting information via a crafted URL, aka Bug ID CSCum03527.
Published 2014-06-21 · Modified
4.0EPSS 0.013