CVE-2015-6349
published 2015-10-30CVE-2015-6349: Cross-site scripting (XSS) vulnerability in the web interface in the Solution Engine in Cisco Secure Access Control Server (ACS) 5.7(0.15) allows remote…
PriorityP419medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.36%
68.5th percentile
Cross-site scripting (XSS) vulnerability in the web interface in the Solution Engine in Cisco Secure Access Control Server (ACS) 5.7(0.15) allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | secure | — | — |
| cisco | secure_access_control_server | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_cisco4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Secure Access Control Server Reflective Cross-Site Scripting Vulnerability
vendor_cisco·2015-10-26·CVSS 4.3
CVE-2015-6349 [MEDIUM] CWE-79 Cisco Secure Access Control Server Reflective Cross-Site Scripting Vulnerability
Cisco Secure Access Control Server Reflective Cross-Site Scripting Vulnerability
A vulnerability in the Cisco Secure Access Control Server (ACS) web interface could allow an unauthenticated, remote attacker to impact the integrity of the system by executing a reflective cross-site scripting (XSS) attack.
The vulnerability is due to a lack of input validation on user-supplied input. An attacker could exploit this vulnerability by sending a crafted URL to the affected system. A successful exploit could allow the attacker to affect the integrity of the system via database manipulation.
Cisco has released software updates that address this vulnerability. Workarounds that mitigate this vulnerability are not available.
This advisory is available at the following link: https://sec.cloudapps.
Cisco
Cisco Secure Access Control Server Reflective Cross-Site Scripting Vulnerability
vendor_cisco
CVE-2015-6349 Cisco Secure Access Control Server Reflective Cross-Site Scripting Vulnerability
CVE-2015-6349: Cisco Secure Access Control Server Reflective Cross-Site Scripting Vulnerability
A vulnerability in the Cisco Secure Access Control Server (ACS) web interface could allow an unauthenticated, remote attacker to impact the integrity of the system by executing a reflective cross-site scripting (XSS) attack. The vulnerability is due to a lack of input validation on user-supplied input. An attacker could exploit this vulnerability by sending a crafted URL to the affected system. A successful exploit could allow the attacker to affect the integrity of the system via database manipulation. Cisco has released software updates that address this vulnerability.
CWE: CWE-79, CWE-79
Bug IDs: CSCuw24705
GHSA
GHSA-7p9r-h26q-4mf3: Cross-site scripting (XSS) vulnerability in the web interface in the Solution Engine in Cisco Secure Access Control Server (ACS) 5
ghsa_unreviewed·2022-05-17
CVE-2015-6349 [MEDIUM] CWE-79 GHSA-7p9r-h26q-4mf3: Cross-site scripting (XSS) vulnerability in the web interface in the Solution Engine in Cisco Secure Access Control Server (ACS) 5
Cross-site scripting (XSS) vulnerability in the web interface in the Solution Engine in Cisco Secure Access Control Server (ACS) 5.7(0.15) allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-10-30
Published