Cisco WebEx Meeting Center CVE-2017-12297 URL Redirection Vulnerability
BID:101985
Info
Cisco WebEx Meeting Center CVE-2017-12297 URL Redirection Vulnerability
| Bugtraq ID: | 101985 |
| Class: | Input Validation Error |
| CVE: |
CVE-2017-12297 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 29 2017 12:00AM |
| Updated: | Dec 19 2017 10:01PM |
| Credit: | Hanson Nottingham, Security Researcher at Blue Shield of California |
| Vulnerable: |
Cisco WebEx Meetings T32.6 Cisco WebEx Meetings T32.4 Cisco WebEx Meetings T32.3 Cisco WebEx Meetings T32 Cisco WebEx Meetings T31SP9 Cisco WebEx Meetings T31SP8 Cisco WebEx Meetings T30SP9 Cisco WebEx Meetings T30SP8 Cisco WebEx Meetings T30SP7 Cisco WebEx Meeting Center 0 |
| Not Vulnerable: | |
Discussion
Cisco WebEx Meeting Center CVE-2017-12297 URL Redirection Vulnerability
Cisco WebEx Meeting Center is prone to a remote URL-redirection vulnerability.
An attacker can leverage this issue by constructing a URI that includes a malicious site redirection. When an unsuspecting victim follows the URI, they may be redirected to an attacker-controlled site; this may aid in phishing attacks.
The issue is being tracked by Cisco Bug ID CSCvf63843.
Cisco WebEx Meeting Center is prone to a remote URL-redirection vulnerability.
An attacker can leverage this issue by constructing a URI that includes a malicious site redirection. When an unsuspecting victim follows the URI, they may be redirected to an attacker-controlled site; this may aid in phishing attacks.
The issue is being tracked by Cisco Bug ID CSCvf63843.
Exploit / POC
Cisco WebEx Meeting Center CVE-2017-12297 URL Redirection Vulnerability
An attacker can exploit this issue by enticing an unsuspecting victim into following a malicious URI.
An attacker can exploit this issue by enticing an unsuspecting victim into following a malicious URI.
Solution / Fix
Cisco WebEx Meeting Center CVE-2017-12297 URL Redirection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Cisco WebEx Meeting Center CVE-2017-12297 URL Redirection Vulnerability
References:
References: