CVE-2015-6434
published 2016-01-08CVE-2015-6434: Cisco Prime Infrastructure does not properly restrict use of IFRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks and…
PriorityP424medium6.1CVSS 3.0
AVNACLPRNUIRSCCLILAN
EPSS
0.88%
54.8th percentile
Cisco Prime Infrastructure does not properly restrict use of IFRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks and unspecified other attacks via a crafted web site, related to a "cross-frame scripting (XFS)" issue, aka Bug ID CSCux64856.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | prime_infrastructure | — | — |
| cisco | prime_infrastructure_frame | — | — |
CVSS provenance
nvdv3.06.1MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_cisco4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Prime Infrastructure Frame Injection Vulnerability
vendor_cisco·2016-01-05·CVSS 4.3
CVE-2015-6434 [MEDIUM] CWE-20 Cisco Prime Infrastructure Frame Injection Vulnerability
Cisco Prime Infrastructure Frame Injection Vulnerability
A vulnerability in the web interface of Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to execute a cross-frame scripting (XFS) attack.
The vulnerability is due to insufficient HTML iframe protection. An attacker could exploit this vulnerability by directing a user to an attacker-controlled web page that contains a malicious HTML iframe. A successful exploit could allow the attacker to conduct click-jacking or other client-side browser attacks.
Cisco has not released software updates that address this vulnerability. There are no workarounds that mitigate this vulnerability.
This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/c
Cisco
Cisco Prime Infrastructure Frame Injection Vulnerability
vendor_cisco
CVE-2015-6434 Cisco Prime Infrastructure Frame Injection Vulnerability
CVE-2015-6434: Cisco Prime Infrastructure Frame Injection Vulnerability
A vulnerability in the web interface of Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to execute a cross-frame scripting (XFS) attack. The vulnerability is due to insufficient HTML iframe protection. An attacker could exploit this vulnerability by directing a user to an attacker-controlled web page that contains a malicious HTML iframe. A successful exploit could allow the attacker to conduct click-jacking or other client-side browser attacks. Cisco has not released software updates that address this vulnerability. There are no
CWE: CWE-20, CWE-20
Bug IDs: CSCux64856
GHSA
GHSA-8m35-36f3-cg86: Cisco Prime Infrastructure does not properly restrict use of IFRAME elements, which makes it easier for remote attackers to conduct clickjacking attac
ghsa_unreviewed·2022-05-17
CVE-2015-6434 [MEDIUM] CWE-79 GHSA-8m35-36f3-cg86: Cisco Prime Infrastructure does not properly restrict use of IFRAME elements, which makes it easier for remote attackers to conduct clickjacking attac
Cisco Prime Infrastructure does not properly restrict use of IFRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks and unspecified other attacks via a crafted web site, related to a "cross-frame scripting (XFS)" issue, aka Bug ID CSCux64856.
GHSA
GHSA-6vqh-26fp-9x33: Cisco Prime Infrastructure 2
ghsa_unreviewed·2022-05-17·CVSS 6.1
CVE-2016-1474 [MEDIUM] CWE-284 GHSA-6vqh-26fp-9x33: Cisco Prime Infrastructure 2
Cisco Prime Infrastructure 2.2(2) does not properly restrict use of IFRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks and unspecified other attacks via a crafted web site, related to a "cross-frame scripting (XFS)" issue, aka Bug ID CSCuw65846, a different vulnerability than CVE-2015-6434.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2016-01-08
Published