CVE-2015-0737
published 2015-06-12CVE-2015-0737: Multiple cross-site scripting (XSS) vulnerabilities in Cisco FireSIGHT System Software 5.3.1.1 allow remote attackers to inject arbitrary web script or HTML…
PriorityP419medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.55%
72.2th percentile
Multiple cross-site scripting (XSS) vulnerabilities in Cisco FireSIGHT System Software 5.3.1.1 allow remote attackers to inject arbitrary web script or HTML via a crafted (1) GET or (2) POST parameter, aka Bug ID CSCuu11099.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | firesight_system_software | — | — |
| openstack | swift | >= 0 < 1.13.1-0ubuntu1.5 | 1.13.1-0ubuntu1.5 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv5.0MEDIUM
vendor_cisco4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco FireSIGHT Management Center Cross-Site Scripting Vulnerability
vendor_cisco·2015-06-08·CVSS 4.3
CVE-2015-0737 [MEDIUM] CWE-79 Cisco FireSIGHT Management Center Cross-Site Scripting Vulnerability
Cisco FireSIGHT Management Center Cross-Site Scripting Vulnerability
A vulnerability in the Cisco FireSIGHT Management Center could allow an authenticated, remote attacker to perform cross-site scripting (XSS) attacks.
The vulnerability is due to insufficient input validation of some parameters passed via HTTP GET or POST methods. An attacker could exploit this vulnerability by intercepting the user packets and injecting malicious code. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected site or allow the attacker to access sensitive browser-based information.
Cisco has confirmed the vulnerability; however, software updates are not available.
To exploit the vulnerability, the attacker may provide a link that directs a user to a
GHSA
GHSA-r6pg-v32r-hh3f: Multiple cross-site scripting (XSS) vulnerabilities in Cisco FireSIGHT System Software 5
ghsa_unreviewed·2022-05-17
CVE-2015-0737 [MEDIUM] CWE-79 GHSA-r6pg-v32r-hh3f: Multiple cross-site scripting (XSS) vulnerabilities in Cisco FireSIGHT System Software 5
Multiple cross-site scripting (XSS) vulnerabilities in Cisco FireSIGHT System Software 5.3.1.1 allow remote attackers to inject arbitrary web script or HTML via a crafted (1) GET or (2) POST parameter, aka Bug ID CSCuu11099.
OSV
swift vulnerabilities
osv·2017-10-11·CVSS 5.0
CVE-2015-5223 swift vulnerabilities
swift vulnerabilities
It was discovered that OpenStack Swift incorrectly handled tempurls. A
remote authenticated user in possession of a tempurl key authorized for PUT
could retrieve other objects in the same Swift account. (CVE-2015-5223)
Romain Le Disez and Örjan Persson discovered that OpenStack Swift
incorrectly closed client connections. A remote attacker could possibly use
this issue to consume resources, resulting in a denial of service.
(CVE-2016-0737, CVE-2016-0738)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-06-12
Published