Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A vulnerability in the web interface of Cisco Jabber for Windows Client could allow an authenticated, local attacker to retrieve user profile information, which could lead to the disclosure of confidential information. The vulnerability is due to a lack of input- and validation-checking mechanisms in the system. An attacker could exploit this vulnerability by issuing specific commands after authenticating to the system. A successful exploit could allow the attacker to view profile information where only certain parameters should be visible. Cisco Bug IDs: CSCve14401.
CVSS Information
N/A
Vulnerability Type
信息暴露
Vulnerability Title
Cisco Jabber for Windows Client 信息泄露漏洞
Vulnerability Description
Cisco Jabber for Windows Client是美国思科(Cisco)公司的一套用于Windows平台的统一通信客户端解决方案的客户端。该方案提供了在线状态显示、即时消息、语音等功能。 Cisco Jabber for Windows Client中的Web界面存在信息泄露漏洞,该漏洞源于程序缺少输入和验证检测机制。本地攻击者可通过在向系统进行身份验证后,发送命令利用该漏洞检索用户配置文件信息。
CVSS Information
N/A
Vulnerability Type
N/A