The XML programmatic interface (XML PI) in Cisco WebEx Meeting Server 1.5(.1.131) and earlier allows remote authenticated users to obtain sensitive meeting information via a crafted URL, aka Bug ID CSCum03527.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://tools.cisco.com/security/center/viewAlert.x?alertId=34663 | vendor advisory |
http://secunia.com/advisories/59263 | third party advisory |
http://www.securityfocus.com/bid/68118 | third party advisory vdb entry |
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3296 | vendor advisory |