CVE-2017-3823 – Cisco WebEx Chrome Extension Remote Command Execution
https://notcve.org/view.php?id=CVE-2017-3823
An issue was discovered in the Cisco WebEx Extension before 1.0.7 on Google Chrome, the ActiveTouch General Plugin Container before 106 on Mozilla Firefox, the GpcContainer Class ActiveX control plugin before 10031.6.2017.0126 on Internet Explorer, and the Download Manager ActiveX control plugin before 2.1.0.10 on Internet Explorer. A vulnerability in these Cisco WebEx browser extensions could allow an unauthenticated, remote attacker to execute arbitrary code with the privileges of the affected browser on an affected system. This vulnerability affects the browser extensions for Cisco WebEx Meetings Server and Cisco WebEx Centers (Meeting Center, Event Center, Training Center, and Support Center) when they are running on Microsoft Windows. The vulnerability is a design defect in an application programing interface (API) response parser within the extension. An attacker that can convince an affected user to visit an attacker-controlled web page or follow an attacker-supplied link with an affected browser could exploit the vulnerability. • http://www.securityfocus.com/bid/95737 http://www.securitytracker.com/id/1037680 https://0patch.blogspot.com/2017/01/micropatching-remote-code-execution-in.html https://blog.filippo.io/webex-extension-vulnerability https://bugs.chromium.org/p/project-zero/issues/detail?id=1096 https://bugs.chromium.org/p/project-zero/issues/detail?id=1100 https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170124-webex https://www.kb.cert.org/vuls/id/909240 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2015-4281
https://notcve.org/view.php?id=CVE-2015-4281
Cross-site request forgery (CSRF) vulnerability in Cisco WebEx Meetings Server 2.5 MR1 allows remote attackers to hijack the authentication of arbitrary users, aka Bug IDs CSCus56150 and CSCus56146. Vulnerabilidad CSRF en Cisco WebEx Meetings Server 2.5 MR1. Permite a atcantes remotos secuestrar la autenticación de usuarios arbitrarios, también conocido como Bug IDs CSCus56150 y CSCus56146. • http://tools.cisco.com/security/center/viewAlert.x?alertId=40021 http://www.securityfocus.com/bid/75979 http://www.securitytracker.com/id/1033016 • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2015-4276
https://notcve.org/view.php?id=CVE-2015-4276
Cisco WebEx Meetings Server 2.5MR1 allows remote authenticated users to execute arbitrary code via a crafted command parameter, aka Bug ID CSCus56138. El servidor Cisco WebEx Meetings Server 2.5MR1, permite a usuarios remotos autenticados ejecutar código arbitrario a través de un parámetro de comando manipulado, también conocido como Bug ID CSCus56138 • http://tools.cisco.com/security/center/viewAlert.x?alertId=39938 http://www.securityfocus.com/bid/75917 http://www.securitytracker.com/id/1032963 • CWE-20: Improper Input Validation •
CVE-2015-0634
https://notcve.org/view.php?id=CVE-2015-0634
Cross-site scripting (XSS) vulnerability in the administrative interface in Cisco WebEx Meetings Server 2.5 and 2.5.0.997 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCuq86310. Una vulnerabilidad de ejecución de comandos en sitios cruzados (XSS) en la interfaz de administración en Cisco WebEx Meetings Server 2.5 y 2.5.0.997 permite a atacantes remotos inyectar secuencias de comandos web arbitrarios o HTML a través de una URL manipulada, también conocido como Bug ID CSCuq86310. • http://tools.cisco.com/security/center/viewAlert.x?alertId=38811 http://www.securityfocus.com/bid/74647 http://www.securitytracker.com/id/1032329 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2015-0668
https://notcve.org/view.php?id=CVE-2015-0668
Cross-site scripting (XSS) vulnerability in the administration portal in Cisco WebEx Meetings Server 2.5 and 2.5.99.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CSCuq66737. Vulnerabilidad XSS en el portal de administración de Cisco WebEx Meetings Server 2.5 y 2.5.99.2 permite a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarios a través de vectores no especificados, también conocido como Bug ID CSCuq66737. • http://tools.cisco.com/security/center/viewAlert.x?alertId=37934 http://www.securitytracker.com/id/1031968 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •