CVE-2015-0668
published 2015-03-20CVE-2015-0668: Cross-site scripting (XSS) vulnerability in the administration portal in Cisco WebEx Meetings Server 2.5 and 2.5.99.2 allows remote attackers to inject…
PriorityP419medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
0.93%
56.5th percentile
Cross-site scripting (XSS) vulnerability in the administration portal in Cisco WebEx Meetings Server 2.5 and 2.5.99.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CSCuq66737.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | webex_meetings_server | — | — |
| cisco | webex_meetings_server | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_cisco4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco WebEx Meetings Server Administrative Portal Cross-Site Scripting Vulnerability
vendor_cisco·2015-03-19·CVSS 4.3
CVE-2015-0668 [MEDIUM] CWE-79 Cisco WebEx Meetings Server Administrative Portal Cross-Site Scripting Vulnerability
Cisco WebEx Meetings Server Administrative Portal Cross-Site Scripting Vulnerability
A vulnerability in the administration portal page of the Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks.
The vulnerability is due to insufficient validation of user-supplied input submitted to the administration portal page of the affected software. An unauthenticated, remote attacker could exploit this vulnerability by convincing a user to visit a malicious website. If successful, the attacker could conduct an XSS attack and execute arbitrary scripts in the user's browser session or gain access to sensitive information.
Cisco has confirmed the vulnerability and released software updates.
To exploit the vulnerability, the attac
GHSA
GHSA-mpm8-hmj3-r984: Cross-site scripting (XSS) vulnerability in the administration portal in Cisco WebEx Meetings Server 2
ghsa_unreviewed·2022-05-17
CVE-2015-0668 [MEDIUM] CWE-79 GHSA-mpm8-hmj3-r984: Cross-site scripting (XSS) vulnerability in the administration portal in Cisco WebEx Meetings Server 2
Cross-site scripting (XSS) vulnerability in the administration portal in Cisco WebEx Meetings Server 2.5 and 2.5.99.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CSCuq66737.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-03-20
Published