CVE-2015-6434Cross-site Scripting in Cisco Prime Infrastructure

Severity
6.1MEDIUMNVD
EPSS
0.2%
top 52.39%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 8
Latest updateMay 17

Description

Cisco Prime Infrastructure does not properly restrict use of IFRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks and unspecified other attacks via a crafted web site, related to a "cross-frame scripting (XFS)" issue, aka Bug ID CSCux64856.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-8m35-36f3-cg86: Cisco Prime Infrastructure does not properly restrict use of IFRAME elements, which makes it easier for remote attackers to conduct clickjacking attac2022-05-17
CVEList
CVE-2015-6434: Cisco Prime Infrastructure does not properly restrict use of IFRAME elements, which makes it easier for remote attackers to conduct clickjacking attac2016-01-08

📋Vendor Advisories

1
Cisco
Cisco Prime Infrastructure Frame Injection Vulnerability2016-01-05
CVE-2015-6434 — Cross-site Scripting in Cisco | cvebase