CVE-2014-8032
https://notcve.org/view.php?id=CVE-2014-8032
The OutlookAction LI in Cisco WebEx Meetings Server allows remote authenticated users to obtain sensitive encrypted-password information via unspecified vectors, aka Bug IDs CSCuj40453 and CSCuj40449. La LI OutlookAction en Cisco WebEx Meetings Server permite a usuarios remotos autenticados obtener información sensible sobre contraseñas cifradas a través de vectores no especificados, también conocido como Bug IDs CSCuj40453 y CSCuj40449. • http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-8032 http://www.securityfocus.com/bid/71947 http://www.securitytracker.com/id/1031517 https://exchange.xforce.ibmcloud.com/vulnerabilities/100564 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2014-8033
https://notcve.org/view.php?id=CVE-2014-8033
The play/modules component in Cisco WebEx Meetings Server allows remote attackers to obtain administrator access via crafted API requests, aka Bug ID CSCuj40421. El componente play/modules en Cisco WebEx Meetings Server permite a atacantes remotos obtener el acceso de administradores a través de solicitudes API manipuladas, también conocido como Bug ID CSCuj40421. • http://secunia.com/advisories/60279 http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-8033 http://www.securityfocus.com/bid/71950 http://www.securitytracker.com/id/1031517 https://exchange.xforce.ibmcloud.com/vulnerabilities/100572 • CWE-287: Improper Authentication •
CVE-2014-3400
https://notcve.org/view.php?id=CVE-2014-3400
Cisco WebEx Meetings Server allows remote authenticated users to obtain sensitive information by reading logs, aka Bug IDs CSCuq36417 and CSCuq40344. Cisco WebEx Meetings Server permite a usuarios remotos autenticados obtener información sensible mediante la lectura de registros, también conocido como Bug IDs CSCuq36417 y CSCuq40344. • http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3400 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2014-3395
https://notcve.org/view.php?id=CVE-2014-3395
Cisco WebEx Meetings Server (WMS) 2.5 allows remote attackers to trigger the download of arbitrary files via a crafted URL, aka Bug ID CSCup10343. Cisco WebEx Meetings Server (WMS) 2.5 permite a atacantes remotos provocar la descarga de ficheros arbitrarios a través de una URL manipulada, también conocido como Bug ID CSCup10343. • http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3395 http://tools.cisco.com/security/center/viewAlert.x?alertId=35876 • CWE-20: Improper Input Validation •
CVE-2014-3302
https://notcve.org/view.php?id=CVE-2014-3302
user.php in Cisco WebEx Meetings Server 1.5(.1.131) and earlier does not properly implement the token timer for authenticated encryption, which allows remote attackers to obtain sensitive information via a crafted URL, aka Bug ID CSCuj81708. user.php en Cisco WebEx Meetings Server 1.5(.1.131) y anteriores no implementa debidamente el reloj de tokens para la codificación autenticada, lo que permite a atacantes remotos obtener información sensible a través de una URL manipulada, también conocido como Bug ID CSCuj81708. • http://secunia.com/advisories/58624 http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3302 http://tools.cisco.com/security/center/viewAlert.x?alertId=35050 http://www.securityfocus.com/bid/68904 http://www.securitytracker.com/id/1030646 https://exchange.xforce.ibmcloud.com/vulnerabilities/94892 • CWE-310: Cryptographic Issues •