CVE-2015-0738
published 2015-05-17CVE-2015-0738: Cross-site scripting (XSS) vulnerability in the Web Tracking Report page on Cisco Web Security Appliance (WSA) devices 8.5.0-497 allows remote attackers to…
PriorityP420medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.55%
72.2th percentile
Cross-site scripting (XSS) vulnerability in the Web Tracking Report page on Cisco Web Security Appliance (WSA) devices 8.5.0-497 allows remote attackers to inject arbitrary web script or HTML via an unspecified field, aka Bug ID CSCuu16008.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | web_security_appliance | — | — |
| openstack | swift | >= 0 < 1.13.1-0ubuntu1.5 | 1.13.1-0ubuntu1.5 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv5.0MEDIUM
vendor_cisco4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Web Security Appliance Web Tracking Report Page Cross-Site Scripting Vulnerability
vendor_cisco·2015-05-15·CVSS 4.3
CVE-2015-0738 [MEDIUM] CWE-79 Cisco Web Security Appliance Web Tracking Report Page Cross-Site Scripting Vulnerability
Cisco Web Security Appliance Web Tracking Report Page Cross-Site Scripting Vulnerability
A vulnerability in the Web Tracking Report page of the Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to perform a cross-site scripting (XSS) attack against the user of the web interface.
The vulnerability is due to improper validation of user-supplied input in a field on the Web Tracking Report page. An attacker could exploit this vulnerability by persuading a user to follow a malicious link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected site or allow the attacker to access sensitive browser-based information.
Cisco has confirmed the vulnerability; however, software updates are not available.
To ex
GHSA
GHSA-9f97-rgpx-3p5f: Cross-site scripting (XSS) vulnerability in the Web Tracking Report page on Cisco Web Security Appliance (WSA) devices 8
ghsa_unreviewed·2022-05-17
CVE-2015-0738 [MEDIUM] CWE-79 GHSA-9f97-rgpx-3p5f: Cross-site scripting (XSS) vulnerability in the Web Tracking Report page on Cisco Web Security Appliance (WSA) devices 8
Cross-site scripting (XSS) vulnerability in the Web Tracking Report page on Cisco Web Security Appliance (WSA) devices 8.5.0-497 allows remote attackers to inject arbitrary web script or HTML via an unspecified field, aka Bug ID CSCuu16008.
OSV
swift vulnerabilities
osv·2017-10-11·CVSS 5.0
CVE-2015-5223 swift vulnerabilities
swift vulnerabilities
It was discovered that OpenStack Swift incorrectly handled tempurls. A
remote authenticated user in possession of a tempurl key authorized for PUT
could retrieve other objects in the same Swift account. (CVE-2015-5223)
Romain Le Disez and Örjan Persson discovered that OpenStack Swift
incorrectly closed client connections. A remote attacker could possibly use
this issue to consume resources, resulting in a denial of service.
(CVE-2016-0737, CVE-2016-0738)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-05-17
Published