CVE-2016-1309: XSS
Published Feb 7, 2016
·Updated
Multiple cross-site scripting (XSS) vulnerabilities in Cisco WebEx Meetings Server 2.5.1.5 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug ID CSCuy01843.
Affected Software
1 affected component
Cisco Webex Meetings Server=2.5.1.5
Event History
Feb 7, 2016
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-1309?
CVE-2016-1309 has been assigned a medium severity level due to its potential for remote cross-site scripting attacks.
2
How do I fix CVE-2016-1309?
To fix CVE-2016-1309, upgrade your Cisco WebEx Meetings Server to the latest version provided by Cisco.
3
What types of vulnerabilities are described in CVE-2016-1309?
CVE-2016-1309 describes multiple cross-site scripting (XSS) vulnerabilities that allow injection of arbitrary web scripts.
4
Which versions of Cisco WebEx Meetings Server are affected by CVE-2016-1309?
CVE-2016-1309 specifically affects Cisco WebEx Meetings Server version 2.5.1.5.
5
Can CVE-2016-1309 be exploited remotely?
Yes, CVE-2016-1309 can be exploited remotely by attackers to execute scripts in the context of another user.