CVE-2015-4208

Cisco WebEx Meeting Center does not properly restrict the content of URLs in GET requests, which allows remote attackers to obtain sensitive information or conduct SQL injection attacks via vectors involving read access to a request, aka Bug ID CSCup88398.
Configurations

Configuration 1 (hide)

cpe:2.3:a:cisco:webex_meeting_center:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2015-06-24 10:59

Updated : 2025-04-12 10:46


NVD link : CVE-2015-4208

Mitre link : CVE-2015-4208

CVE.ORG link : CVE-2015-4208


JSON object : View

Products Affected

cisco

  • webex_meeting_center
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

CWE-200

Exposure of Sensitive Information to an Unauthorized Actor