ID

VAR-201507-0536


CVE

CVE-2015-4249


TITLE

Cisco WebEx Meeting Center Vulnerable to cross-site scripting

Trust: 0.8

sources: JVNDB: JVNDB-2015-003552

DESCRIPTION

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue in customer-controlled software. Notes: none. Cisco WebEx Meeting Center Contains a cross-site scripting vulnerability. Vendors have confirmed this vulnerability Bug ID CSCuv01955 It is released as.By a third party (1) GET Or (2) POST Via any unspecified parameters to the request Web Script or HTML May be inserted. An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks. This issue is being tracked by Cisco Bug ID CSCuv01955. The product invites others to join the meeting via email or instant messaging (IM), enabling online product demonstrations, information sharing, and more

Trust: 1.98

sources: NVD: CVE-2015-4249 // JVNDB: JVNDB-2015-003552 // BID: 75709 // VULHUB: VHN-82210

AFFECTED PRODUCTS

vendor:ciscomodel:webex meeting centerscope: - version: -

Trust: 0.8

vendor:ciscomodel:webex meeting centerscope:eqversion: -

Trust: 0.6

vendor:ciscomodel:webex meeting centerscope:eqversion:0

Trust: 0.3

sources: BID: 75709 // JVNDB: JVNDB-2015-003552 // CNNVD: CNNVD-201507-356

CVSS

SEVERITY

CVSSV2

CVSSV3

NVD: CVE-2015-4249
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201507-356
value: MEDIUM

Trust: 0.6

NVD: CVE-2015-4249
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.8

sources: JVNDB: JVNDB-2015-003552 // CNNVD: CNNVD-201507-356

PROBLEMTYPE DATA

problemtype:CWE-79

Trust: 0.8

sources: JVNDB: JVNDB-2015-003552

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201507-356

TYPE

XSS

Trust: 0.6

sources: CNNVD: CNNVD-201507-356

CONFIGURATIONS

sources: JVNDB: JVNDB-2015-003552

PATCH

title:39782url:http://tools.cisco.com/security/center/viewAlert.x?alertId=39782

Trust: 0.8

sources: JVNDB: JVNDB-2015-003552

EXTERNAL IDS

db:NVDid:CVE-2015-4249

Trust: 2.8

db:JVNDBid:JVNDB-2015-003552

Trust: 0.8

db:CNNVDid:CNNVD-201507-356

Trust: 0.7

db:BIDid:75709

Trust: 0.4

db:SECTRACKid:1032862

Trust: 0.1

db:VULHUBid:VHN-82210

Trust: 0.1

sources: VULHUB: VHN-82210 // BID: 75709 // JVNDB: JVNDB-2015-003552 // CNNVD: CNNVD-201507-356 // NVD: CVE-2015-4249

REFERENCES

url:http://tools.cisco.com/security/center/viewalert.x?alertid=39782

Trust: 0.9

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2015-4249

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2015-4249

Trust: 0.8

url:http://www.cisco.com/

Trust: 0.3

url:http://www.webex.com/products/enterprise_meetings.html

Trust: 0.3

url:http://www.securitytracker.com/id/1032862

Trust: 0.1

sources: VULHUB: VHN-82210 // BID: 75709 // JVNDB: JVNDB-2015-003552 // CNNVD: CNNVD-201507-356

CREDITS

Cisco

Trust: 0.3

sources: BID: 75709

SOURCES

db:VULHUBid:VHN-82210
db:BIDid:75709
db:JVNDBid:JVNDB-2015-003552
db:CNNVDid:CNNVD-201507-356
db:NVDid:CVE-2015-4249

LAST UPDATE DATE

2024-08-14T14:52:19.453000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-82210date:2015-07-23T00:00:00
db:BIDid:75709date:2015-07-13T00:00:00
db:JVNDBid:JVNDB-2015-003552date:2015-07-14T00:00:00
db:CNNVDid:CNNVD-201507-356date:2015-07-14T00:00:00
db:NVDid:CVE-2015-4249date:2023-11-07T02:25:49.483

SOURCES RELEASE DATE

db:VULHUBid:VHN-82210date:2015-07-13T00:00:00
db:BIDid:75709date:2015-07-13T00:00:00
db:JVNDBid:JVNDB-2015-003552date:2015-07-14T00:00:00
db:CNNVDid:CNNVD-201507-356date:2015-07-14T00:00:00
db:NVDid:CVE-2015-4249date:2015-07-13T10:59:00.077