CVE-2015-0634
published 2015-05-15CVE-2015-0634: Cross-site scripting (XSS) vulnerability in the administrative interface in Cisco WebEx Meetings Server 2.5 and 2.5.0.997 allows remote attackers to inject…
PriorityP422medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
2.16%
80.1th percentile
Cross-site scripting (XSS) vulnerability in the administrative interface in Cisco WebEx Meetings Server 2.5 and 2.5.0.997 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCuq86310.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | webex_meetings_server | — | — |
| cisco | webex_meetings_server | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_cisco4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7w8r-vmhh-7vf4: Cross-site scripting (XSS) vulnerability in the administrative interface in Cisco WebEx Meetings Server 2
ghsa_unreviewed·2022-05-17
CVE-2015-0634 [MEDIUM] CWE-79 GHSA-7w8r-vmhh-7vf4: Cross-site scripting (XSS) vulnerability in the administrative interface in Cisco WebEx Meetings Server 2
Cross-site scripting (XSS) vulnerability in the administrative interface in Cisco WebEx Meetings Server 2.5 and 2.5.0.997 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCuq86310.
Cisco
Cisco WebEx Meetings Server Cross-Site Scripting Vulnerability
vendor_cisco·2015-05-13·CVSS 4.3
CVE-2015-0634 [MEDIUM] CWE-79 Cisco WebEx Meetings Server Cross-Site Scripting Vulnerability
Cisco WebEx Meetings Server Cross-Site Scripting Vulnerability
A vulnerability within the administrative interface of Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to conduct cross-site scripting attacks.
The vulnerability is due to insufficient validation of user-supplied input submitted to an affected device. An unauthenticated, remote attacker could exploit this vulnerability by convincing a user to follow a malicious link or attacker-controlled web page. A successful exploit could allow an attacker to execute arbitrary script or HTML code on the user's browser within the context of the affected site.
Cisco has confirmed the vulnerability and software updates are available.
To exploit the vulnerability, the attacker may provide a link that directs a us
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-05-15
Published