Cisco WebEx Meetings Server CVE-2014-3395 Arbitrary File Download Vulnerabilitiy
BID:70181
Info
Cisco WebEx Meetings Server CVE-2014-3395 Arbitrary File Download Vulnerabilitiy
| Bugtraq ID: | 70181 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-3395 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 29 2014 12:00AM |
| Updated: | Oct 01 2014 12:05AM |
| Credit: | Cisco |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Cisco WebEx Meetings Server CVE-2014-3395 Arbitrary File Download Vulnerabilitiy
Cisco WebEx Meetings Server is prone to an arbitrary file-download vulnerability.
An attacker can exploit this issue to download arbitrary files from the Web server and obtain potentially sensitive information.
This issue is being tracked by Cisco bug ID CSCup10343.
Cisco WebEx Meetings Server is prone to an arbitrary file-download vulnerability.
An attacker can exploit this issue to download arbitrary files from the Web server and obtain potentially sensitive information.
This issue is being tracked by Cisco bug ID CSCup10343.
Exploit / POC
Cisco WebEx Meetings Server CVE-2014-3395 Arbitrary File Download Vulnerabilitiy
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
Cisco WebEx Meetings Server CVE-2014-3395 Arbitrary File Download Vulnerabilitiy
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Cisco WebEx Meetings Server CVE-2014-3395 Arbitrary File Download Vulnerabilitiy
References:
References:
- Cisco Homepage (Cisco )