4.3
CVSSv2

CVE-2013-5563

Published: 06/11/2013 Updated: 07/11/2013
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in Query/NewQueryResult.jsp in Cisco Security Monitoring, Analysis and Response System (CS-MARS) allows remote malicious users to inject arbitrary web script or HTML via the isnowLatency parameter, aka Bug ID CSCul16173.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco security monitoring analysis and response system

Exploits

A cross site scripting vulnerability has been found in Cisco Security Monitoring, Analysis and Response System The issue is due to the input passed via several fields (eg: isnowLatency) to the /Query/NewQueryResultjsp page are not properly sanitised before being returned to the user Other pages could be affected by this issue ...