6.1
CVSSv3

CVE-2015-6434

Published: 08/01/2016 Updated: 07/12/2016
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cisco Prime Infrastructure does not properly restrict use of IFRAME elements, which makes it easier for remote malicious users to conduct clickjacking attacks and unspecified other attacks via a crafted web site, related to a "cross-frame scripting (XFS)" issue, aka Bug ID CSCux64856.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco prime infrastructure 2.2\\(2\\)

Vendor Advisories

A vulnerability in the web interface of Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to execute a cross-frame scripting (XFS) attack The vulnerability is due to insufficient HTML iframe protection An attacker could exploit this vulnerability by directing a user to an attacker-controlled web page that contains a mal ...