Cisco WebEx Training Center provides different error messages for registration attempts depending on whether the e-mail address exists, which allows remote attackers to enumerate attendees via a series of requests, aka Bug ID CSCul36003.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.securitytracker.com/id/1029492 | vdb entry third party advisory |
http://osvdb.org/100913 | vdb entry |
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-6968 | vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/89688 | vdb entry |
http://tools.cisco.com/security/center/viewAlert.x?alertId=32147 | vendor advisory |