4.3
CVSSv2

CVE-2015-0737

Published: 12/06/2015 Updated: 04/01/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in Cisco FireSIGHT System Software 5.3.1.1 allow remote malicious users to inject arbitrary web script or HTML via a crafted (1) GET or (2) POST parameter, aka Bug ID CSCuu11099.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco firesight system software 5.3.1.1

Vendor Advisories

A vulnerability in the Cisco FireSIGHT Management Center could allow an authenticated, remote attacker to perform cross-site scripting (XSS) attacks The vulnerability is due to insufficient input validation of some parameters passed via HTTP GET or POST methods An attacker could exploit this vulnerability by intercepting the user packets and in ...