CVE-2016-1446: SQL Injection
Published Jul 15, 2016
·Updated
SQL injection vulnerability in Cisco WebEx Meetings Server 2.6 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCuy83200.
Affected Software
2 affected components
Cisco Webex Meetings Server=2.6.0
Cisco Webex Meetings Server=2.6.1.39
Event History
Jul 15, 2016
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-1446?
CVE-2016-1446 is a high severity vulnerability allowing remote authenticated users to execute arbitrary SQL commands.
2
How do I fix CVE-2016-1446?
To fix CVE-2016-1446, upgrade the Cisco WebEx Meetings Server to version 2.6.1.39 or later.
3
Who is affected by CVE-2016-1446?
CVE-2016-1446 affects Cisco WebEx Meetings Server version 2.6.0 and 2.6.1.39.
4
What types of attacks can exploit CVE-2016-1446?
CVE-2016-1446 can be exploited through SQL injection attacks by authenticated users.
5
What impact does CVE-2016-1446 have on systems?
Exploitation of CVE-2016-1446 allows attackers to execute arbitrary SQL commands, potentially compromising the database.