CVE-2014-3395: Input Validation
Published Sep 30, 2014
·Updated
Cisco WebEx Meetings Server (WMS) 2.5 allows remote attackers to trigger the download of arbitrary files via a crafted URL, aka Bug ID CSCup10343.
Affected Software
1 affected component
Cisco Webex Meetings Server=2.5
Event History
Sep 30, 2014
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-3395?
CVE-2014-3395 has been classified with a moderate severity level.
2
How do I fix CVE-2014-3395?
To fix CVE-2014-3395, update to the patched version of Cisco WebEx Meetings Server 2.6 or later.
3
What type of attack does CVE-2014-3395 enable?
CVE-2014-3395 enables remote attackers to trigger the download of arbitrary files through a specially crafted URL.
4
Who is affected by CVE-2014-3395?
CVE-2014-3395 affects users of Cisco WebEx Meetings Server version 2.5.
5
When was CVE-2014-3395 disclosed?
CVE-2014-3395 was disclosed in July 2014.