CVE-2015-0589
published 2015-02-07CVE-2015-0589: The administrative web interface in Cisco WebEx Meetings Server 1.0 through 1.5 allows remote authenticated users to execute arbitrary OS commands with root…
PriorityP355critical9CVSS 2.0
AVNACLAuSCCICAC
EPSS
3.44%
87.7th percentile
The administrative web interface in Cisco WebEx Meetings Server 1.0 through 1.5 allows remote authenticated users to execute arbitrary OS commands with root privileges via unspecified fields, aka Bug ID CSCuj40460.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | webex_meetings_server | — | — |
| cisco | webex_meetings_server | — | — |
| cisco | webex_meetings_server | — | — |
| cisco | webex_meetings_server | — | — |
CVSS provenance
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vendor_cisco9.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hggx-9h6r-3w8r: The administrative web interface in Cisco WebEx Meetings Server 1
ghsa_unreviewed·2022-05-17
CVE-2015-0589 [HIGH] CWE-20 GHSA-hggx-9h6r-3w8r: The administrative web interface in Cisco WebEx Meetings Server 1
The administrative web interface in Cisco WebEx Meetings Server 1.0 through 1.5 allows remote authenticated users to execute arbitrary OS commands with root privileges via unspecified fields, aka Bug ID CSCuj40460.
Cisco
Cisco WebEx Meetings Server Command Injection Vulnerability
vendor_cisco·2015-02-04·CVSS 9.0
CVE-2015-0589 [CRITICAL] CWE-20 Cisco WebEx Meetings Server Command Injection Vulnerability
Cisco WebEx Meetings Server Command Injection Vulnerability
A vulnerability in the administrative web interface of Cisco WebEx Meetings Server could allow an authenticated, remote attacker to execute arbitrary commands on the affected system and on the devices managed by the affected system.
The vulnerability is due to improper user input validation. An attacker could exploit this vulnerability by crafting input into the affected fields of the web interface.
Cisco has released software updates that address this vulnerability. Workarounds that mitigate this vulnerability are not available.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150204-wbx
Cisco
Cisco WebEx Meetings Server Command Injection Vulnerability
vendor_cisco
CVE-2015-0589 Cisco WebEx Meetings Server Command Injection Vulnerability
CVE-2015-0589: Cisco WebEx Meetings Server Command Injection Vulnerability
A vulnerability in the administrative web interface of Cisco WebEx Meetings Server could allow an authenticated, remote attacker to execute arbitrary commands on the affected system and on the devices managed by the affected system. The vulnerability is due to improper user input validation. An attacker could exploit this vulnerability by crafting input into the affected fields of the web interface. Cisco has released software updates that address this vulnerability.
CWE: CWE-20, CWE-20
Bug IDs: CSCuj40460, CSCuj40460
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/62799http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150204-wbxhttp://www.securityfocus.com/bid/72493http://www.securitytracker.com/id/1031692https://exchange.xforce.ibmcloud.com/vulnerabilities/100719http://secunia.com/advisories/62799http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150204-wbxhttp://www.securityfocus.com/bid/72493http://www.securitytracker.com/id/1031692https://exchange.xforce.ibmcloud.com/vulnerabilities/100719
2015-02-07
Published