CVE-2015-4198
published 2015-06-20CVE-2015-4198: Cross-site scripting (XSS) vulnerability in the web framework on Cisco Web Security Appliance (WSA) devices with software 8.5.0-497 allows remote attackers to…
PriorityP421medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
2.16%
80.2th percentile
Cross-site scripting (XSS) vulnerability in the web framework on Cisco Web Security Appliance (WSA) devices with software 8.5.0-497 allows remote attackers to inject arbitrary web script or HTML via an unspecified HTTP header, aka Bug ID CSCuu24409.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | web_security_appliance | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_cisco4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-v5x3-2xr4-f8xj: Cross-site scripting (XSS) vulnerability in the web framework on Cisco Web Security Appliance (WSA) devices with software 8
ghsa_unreviewed·2022-05-17
CVE-2015-4198 [MEDIUM] CWE-79 GHSA-v5x3-2xr4-f8xj: Cross-site scripting (XSS) vulnerability in the web framework on Cisco Web Security Appliance (WSA) devices with software 8
Cross-site scripting (XSS) vulnerability in the web framework on Cisco Web Security Appliance (WSA) devices with software 8.5.0-497 allows remote attackers to inject arbitrary web script or HTML via an unspecified HTTP header, aka Bug ID CSCuu24409.
Cisco
Cisco Web Security Appliance Web Framework HTTP Header Injection Vulnerability
vendor_cisco·2015-06-19·CVSS 4.3
CVE-2015-4198 [MEDIUM] CWE-20 Cisco Web Security Appliance Web Framework HTTP Header Injection Vulnerability
Cisco Web Security Appliance Web Framework HTTP Header Injection Vulnerability
A vulnerability in the web framework of Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to inject a crafted HTTP header that could introduce arbitrary code into the web interface.
The vulnerability is due to insufficient validation of user input before it is used as an HTTP header value. An attacker could exploit this vulnerability by persuading a user to access a crafted URL. A successful exploit could allow the attacker to execute arbitrary HTML or script in a targeted user's browser.
Cisco has confirmed the vulnerability; however, software updates are not available.
To exploit the vulnerability, the attacker may provide a link that directs a user to a malicious site and
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-06-20
Published