4.3
CVSSv2

CVE-2015-6400

Published: 13/12/2015 Updated: 28/11/2016
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in Cisco Emergency Responder 10.5(1a) allow remote malicious users to inject arbitrary web script or HTML via unspecified fields, aka Bug ID CSCuv25547.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco emergency responder 10.5\\(1a\\)

Vendor Advisories

A vulnerability in the web framework of Cisco Emergency Responder Software could allow an unauthenticated, remote attacker to execute a stored cross-site scripting (XSS) attack against the user of the web interface The vulnerability is due to insufficient validation on the input fields of a web form An attacker could exploit this vulnerability ...