CVE-2015-6346
published 2015-10-30CVE-2015-6346: Cross-site scripting (XSS) vulnerability in Cisco Secure Access Control Server (ACS) 5.7(0.15) allows remote attackers to inject arbitrary web script or HTML…
PriorityP419medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.36%
68.5th percentile
Cross-site scripting (XSS) vulnerability in Cisco Secure Access Control Server (ACS) 5.7(0.15) allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | secure | — | — |
| cisco | secure_access_control_server | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_cisco4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Secure Access Control Server Dom-Based Cross-Site Scripting Vulnerability
vendor_cisco·2015-10-26·CVSS 4.3
CVE-2015-6346 [MEDIUM] CWE-79 Cisco Secure Access Control Server Dom-Based Cross-Site Scripting Vulnerability
Cisco Secure Access Control Server Dom-Based Cross-Site Scripting Vulnerability
A vulnerability in the Cisco Secure Access Control Server (ACS) web interface could allow an unauthenticated, remote attacker to impact the integrity of the system by executing a Document Object Model (DOM)-based, environment or client side, cross-site scripting (XSS) attack.
The vulnerability is due to a lack of input validation on user-supplied data within the DOM input. An attacker could exploit this vulnerability by sending crafted URLs that contain malicious DOM statements to the affected system. A successful exploit could allow the attacker to effect the integrity of the system via database manipulation.
Cisco has not released software updates that address this vulnerability. Workarounds that mitigate
Cisco
Cisco Secure Access Control Server Dom-Based Cross-Site Scripting Vulnerability
vendor_cisco
CVE-2015-6346 Cisco Secure Access Control Server Dom-Based Cross-Site Scripting Vulnerability
CVE-2015-6346: Cisco Secure Access Control Server Dom-Based Cross-Site Scripting Vulnerability
A vulnerability in the Cisco Secure Access Control Server (ACS) web interface could allow an unauthenticated, remote attacker to impact the integrity of the system by executing a Document Object Model (DOM)-based, environment or client side, cross-site scripting (XSS) attack. The vulnerability is due to a lack of input validation on user-supplied data within the DOM input. An attacker could exploit this vulnerability by sending crafted URLs that contain malicious DOM statements to the affected system. A successful exploit could allow the attacker to effect the integrity of the system via database manipulation. Cisco has not released software updates that address this vulnerability.
CWE: CWE-79, C
GHSA
GHSA-h5jc-jmf9-72gh: Cross-site scripting (XSS) vulnerability in Cisco Secure Access Control Server (ACS) 5
ghsa_unreviewed·2022-05-17
CVE-2015-6346 [MEDIUM] CWE-79 GHSA-h5jc-jmf9-72gh: Cross-site scripting (XSS) vulnerability in Cisco Secure Access Control Server (ACS) 5
Cross-site scripting (XSS) vulnerability in Cisco Secure Access Control Server (ACS) 5.7(0.15) allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-10-30
Published