Release date:
Updated on: 2013-01-26
Affected Systems:
Cisco WebEx Social
Description:
--------------------------------------------------------------------------------
Bugtraq id: 57534
CVE (CAN) ID: CVE-2012-6397
Cisco WebEx Social is an enterprise collaboration platform.
Cisco WebEx Social has an XSS vulnerability in the RSS service link, which allows remote attackers to inject arbitrary web scripts or HTML through a specially crafted RSS service link.
<* Source: Cisco
Link: http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2012-6397
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Cisco
-----
Cisco has released a Security Bulletin (CVE-2012-6397) and patches for this:
CVE-2012-6397: Cisco WebEx Social Cross-site Scripting Vulnerability in RSS Service
Link: http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2012-6397