CVE-2014-3296
published 2014-06-21CVE-2014-3296: The XML programmatic interface (XML PI) in Cisco WebEx Meeting Server 1.5(.1.131) and earlier allows remote authenticated users to obtain sensitive meeting…
PriorityP418medium4CVSS 2.0
AVNACLAuSCPINAN
EPSS
1.30%
67.0th percentile
The XML programmatic interface (XML PI) in Cisco WebEx Meeting Server 1.5(.1.131) and earlier allows remote authenticated users to obtain sensitive meeting information via a crafted URL, aka Bug ID CSCum03527.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | webex_meetings_server | <= 1.5\(.1.131\) | — |
| cisco | webex_meetings_server | — | — |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
vendor_cisco4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco WebEx Meeting Server Sensitive Information Disclosure Vulnerability
vendor_cisco·2014-06-20·CVSS 4.0
CVE-2014-3296 [MEDIUM] CWE-200 Cisco WebEx Meeting Server Sensitive Information Disclosure Vulnerability
Cisco WebEx Meeting Server Sensitive Information Disclosure Vulnerability
A vulnerability in the XML programmatic interface (XML PI) of Cisco WebEx Meeting Server could allow an authenticated, remote attacker to access sensitive information.
The vulnerability is due to disclosure of the meeting information. An attacker could exploit this vulnerability by sending a crafted URL request to a vulnerable device.
Cisco has confirmed the vulnerability in a security notice and released software updates.
To exploit this vulnerability, an attacker must authenticate to an affected device. This access requirement decreases the likelihood of a successful exploit.
Cisco indicates through the CVSS score that functional exploit code exists; however, the code is not known to be publicly available.
GHSA
GHSA-q98q-vph7-x77f: The XML programmatic interface (XML PI) in Cisco WebEx Meeting Server 1
ghsa_unreviewed·2022-05-17
CVE-2014-3296 [MEDIUM] CWE-200 GHSA-q98q-vph7-x77f: The XML programmatic interface (XML PI) in Cisco WebEx Meeting Server 1
The XML programmatic interface (XML PI) in Cisco WebEx Meeting Server 1.5(.1.131) and earlier allows remote authenticated users to obtain sensitive meeting information via a crafted URL, aka Bug ID CSCum03527.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/59263http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3296http://tools.cisco.com/security/center/viewAlert.x?alertId=34663http://www.securityfocus.com/bid/68118http://secunia.com/advisories/59263http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3296http://tools.cisco.com/security/center/viewAlert.x?alertId=34663http://www.securityfocus.com/bid/68118
2014-06-21
Published