CVE-2016-1293
published 2016-01-16CVE-2016-1293: Multiple cross-site scripting (XSS) vulnerabilities in the Management Center in Cisco FireSIGHT System Software 6.0.0 and 6.0.1 allow remote attackers to…
PriorityP423medium6.1CVSS 3.0
AVNACLPRNUIRSCCLILAN
EPSS
1.12%
62.6th percentile
Multiple cross-site scripting (XSS) vulnerabilities in the Management Center in Cisco FireSIGHT System Software 6.0.0 and 6.0.1 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug ID CSCux40414.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | firesight_management_center_stored | — | — |
| cisco | firesight_system_software | — | — |
| cisco | firesight_system_software | — | — |
CVSS provenance
nvdv3.06.1MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_cisco4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-945r-v7jc-f447: Multiple cross-site scripting (XSS) vulnerabilities in the Management Center in Cisco FireSIGHT System Software 6
ghsa_unreviewed·2022-05-17
CVE-2016-1293 [MEDIUM] CWE-79 GHSA-945r-v7jc-f447: Multiple cross-site scripting (XSS) vulnerabilities in the Management Center in Cisco FireSIGHT System Software 6
Multiple cross-site scripting (XSS) vulnerabilities in the Management Center in Cisco FireSIGHT System Software 6.0.0 and 6.0.1 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug ID CSCux40414.
Cisco
Cisco FireSIGHT Management Center Stored Cross-Site Scripting Vulnerabilities
vendor_cisco·2016-01-15·CVSS 4.3
CVE-2016-1293 [MEDIUM] CWE-79 Cisco FireSIGHT Management Center Stored Cross-Site Scripting Vulnerabilities
Cisco FireSIGHT Management Center Stored Cross-Site Scripting Vulnerabilities
Multiple vulnerabilities in the web framework of Cisco FireSIGHT Management Center could allow an unauthenticated, remote attacker to execute a stored cross-site scripting (XSS) attack against a user of the Cisco FireSIGHT Management Center web interface.
The vulnerabilities are due to improper sanitization of parameter values. An attacker could exploit these vulnerabilities by injecting malicious code into an affected parameter and persuading a user to access a web page that requires reading or executing the parameter.
Cisco released software updates that address these vulnerabilities. There are no workarounds that mitigate these vulnerabilities.
This advisory is available at the following link: https://sec
Cisco
Cisco FireSIGHT Management Center Stored Cross-Site Scripting Vulnerabilities
vendor_cisco
CVE-2016-1293 Cisco FireSIGHT Management Center Stored Cross-Site Scripting Vulnerabilities
CVE-2016-1293: Cisco FireSIGHT Management Center Stored Cross-Site Scripting Vulnerabilities
Multiple vulnerabilities in the web framework of Cisco FireSIGHT Management Center could allow an unauthenticated, remote attacker to execute a stored cross-site scripting (XSS) attack against a user of the Cisco FireSIGHT Management Center web interface. The vulnerabilities are due to improper sanitization of parameter values. An attacker could exploit these vulnerabilities by injecting malicious code into an affected parameter and persuading a user to access a web page that requires reading or executing the parameter. Cisco released software updates that address these vulnerabilities. There are no
CWE: CWE-79, CWE-79
Bug IDs: CSCuw89080, CSCuw89129, CSCux40414, CSCuw89080, CSCuw89129
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2016-01-16
Published