CVE-2016-1331
published 2016-02-15CVE-2016-1331: Multiple cross-site scripting (XSS) vulnerabilities in Cisco Emergency Responder 11.5(0.99833.5) allow remote attackers to inject arbitrary web script or HTML…
PriorityP424medium6.1CVSS 3.0
AVNACLPRNUIRSCCLILAN
EPSS
1.01%
59.0th percentile
Multiple cross-site scripting (XSS) vulnerabilities in Cisco Emergency Responder 11.5(0.99833.5) allow remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug ID CSCuy10766.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | emergency_responder | — | — |
| msrc | system_center_2016_operations_manager | — | — |
| sun | opensolaris | — | — |
CVSS provenance
nvdv3.06.1MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_msrc5.4HIGH
vendor_cisco4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
System Center Operations Manager Spoofing Vulnerability
vendor_msrc·2020-06-09·CVSS 5.4
CVE-2020-1331 [MEDIUM] System Center Operations Manager Spoofing Vulnerability
System Center Operations Manager Spoofing Vulnerability
Description: A spoofing vulnerability exists when System Center Operations Manager (SCOM) does not properly sanitize a specially crafted web request to an affected SCOM 2016 Web Console instance. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to an affected SCOM 2016 Web Console instance.
The attacker who successfully exploited the vulnerability could then perform cross-site scripting attacks on affected systems and run script in the security context of the current user. These attacks could allow the attacker to read content that the attacker is not authorized to read, use the victim's identity to take actions on the SCOM 2016 Web Console instance on behalf of the user, such as change
Cisco
Cisco Emergency Responder Cross-Site Scripting Vulnerability
vendor_cisco·2016-02-15·CVSS 4.3
CVE-2016-1331 [MEDIUM] CWE-79 Cisco Emergency Responder Cross-Site Scripting Vulnerability
Cisco Emergency Responder Cross-Site Scripting Vulnerability
A vulnerability in the web framework code of Cisco Emergency Responder could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the user of the web interface of an affected system.
The vulnerability is due to insufficient input validation of some parameters passed to the web server. An attacker could exploit this vulnerability by convincing the user to access a malicious link or by intercepting the user request and injecting malicious code. An exploit could allow the attacker to execute arbitrary code in the context of the affected site or allow the attacker to access sensitive browser-based information.
Cisco has not released software updates that address this vulnerability. Worka
Cisco
Cisco Emergency Responder Cross-Site Scripting Vulnerability
vendor_cisco
CVE-2016-1331 Cisco Emergency Responder Cross-Site Scripting Vulnerability
CVE-2016-1331: Cisco Emergency Responder Cross-Site Scripting Vulnerability
A vulnerability in the web framework code of Cisco Emergency Responder could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the user of the web interface of an affected system. The vulnerability is due to insufficient input validation of some parameters passed to the web server. An attacker could exploit this vulnerability by convincing the user to access a malicious link or by intercepting the user request and injecting malicious code. An exploit could allow the attacker to execute arbitrary code in the context of the affected site or allow the attacker to access sensitive browser-based information. Cisco has not released software updates that address this vulnerab
GHSA
GHSA-vqhf-xvfq-fjhw: Multiple cross-site scripting (XSS) vulnerabilities in Cisco Emergency Responder 11
ghsa_unreviewed·2022-05-17
CVE-2016-1331 [MEDIUM] CWE-79 GHSA-vqhf-xvfq-fjhw: Multiple cross-site scripting (XSS) vulnerabilities in Cisco Emergency Responder 11
Multiple cross-site scripting (XSS) vulnerabilities in Cisco Emergency Responder 11.5(0.99833.5) allow remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug ID CSCuy10766.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2016-02-15
Published