First published: Fri Jul 15 2016(Updated: )
SQL injection vulnerability in Cisco WebEx Meetings Server 2.6 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCuy83200.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Webex Meetings Server | =2.6.0 | |
Cisco Webex Meetings Server | =2.6.1.39 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-1446 is a high severity vulnerability allowing remote authenticated users to execute arbitrary SQL commands.
To fix CVE-2016-1446, upgrade the Cisco WebEx Meetings Server to version 2.6.1.39 or later.
CVE-2016-1446 affects Cisco WebEx Meetings Server version 2.6.0 and 2.6.1.39.
CVE-2016-1446 can be exploited through SQL injection attacks by authenticated users.
Exploitation of CVE-2016-1446 allows attackers to execute arbitrary SQL commands, potentially compromising the database.