CVE-2013-6709: Infoleak
Published Dec 14, 2013
·Updated
The registration component in Cisco WebEx Training Center provides the training-session URL before payment is completed, which allows remote attackers to bypass intended access restrictions and join an audio conference by entering credential fields from this URL, aka Bug ID CSCul57111.
Affected Software
1 affected component
Cisco Webex Training Center
Event History
Dec 14, 2013
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Data Sourced
via NVD·10:55 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2013-6709?
CVE-2013-6709 is classified as a medium severity vulnerability.
2
How do I fix CVE-2013-6709?
To fix CVE-2013-6709, users should update to the latest version of Cisco WebEx Training Center.
3
Who is affected by CVE-2013-6709?
CVE-2013-6709 affects users of Cisco WebEx Training Center.
4
What type of vulnerability is CVE-2013-6709?
CVE-2013-6709 is a security vulnerability that allows unauthorized access to audio conferences.
5
Can CVE-2013-6709 be exploited remotely?
Yes, CVE-2013-6709 can be exploited by remote attackers without requiring local access.