The Forgot Password feature in Cisco WebEx Meetings Server 1.5(.1.131) and earlier allows remote attackers to enumerate administrative accounts via crafted packets, aka Bug IDs CSCuj67166 and CSCuj67159.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/100658 | vdb entry |
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2015-0597 | vendor advisory |
http://tools.cisco.com/security/center/viewAlert.x?alertId=37240 | vendor advisory |
http://www.securityfocus.com/bid/72373 | vdb entry third party advisory |
http://www.securitytracker.com/id/1031678 | vdb entry third party advisory |