CVE-2016-1451
published 2016-07-15CVE-2016-1451: Cross-site scripting (XSS) vulnerability in the web-based management interface in Cisco Meeting Server (formerly Acano Conferencing Server) 1.7 through 1.9…
PriorityP425medium6.1CVSS 3.0
AVNACLPRNUIRSCCLILAN
EPSS
0.77%
51.6th percentile
Cross-site scripting (XSS) vulnerability in the web-based management interface in Cisco Meeting Server (formerly Acano Conferencing Server) 1.7 through 1.9 allows remote attackers to inject arbitrary web script or HTML via crafted parameters, aka Bug ID CSCva19922.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | meeting_server | — | — |
| cisco | meeting_server | — | — |
| cisco | meeting_server | — | — |
| cisco | meeting_server_persistent | — | — |
CVSS provenance
nvdv3.06.1MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_cisco4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Meeting Server Persistent Cross-Site Scripting Vulnerability
vendor_cisco·2016-07-15·CVSS 4.3
CVE-2016-1451 [MEDIUM] CWE-79 Cisco Meeting Server Persistent Cross-Site Scripting Vulnerability
Cisco Meeting Server Persistent Cross-Site Scripting Vulnerability
A vulnerability in the web bridge that offers video via a web interface of Cisco Meeting Server Software, formerly Acano Conferencing Server, could allow an unauthenticated, remote attacker to conduct a persistent cross-site scripting (XSS) attack against a user of the web interface of an affected system.
The vulnerability is due to improper input validation of certain parameters that are passed to an affected device via an HTTP request. An attacker could exploit this vulnerability by persuading a user to follow a malicious link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected management interface or allow the attacker to access sensitive browser-based informat
Cisco
Cisco Meeting Server Persistent Cross-Site Scripting Vulnerability
vendor_cisco
CVE-2016-1451 Cisco Meeting Server Persistent Cross-Site Scripting Vulnerability
CVE-2016-1451: Cisco Meeting Server Persistent Cross-Site Scripting Vulnerability
A vulnerability in the web bridge that offers video via a web interface of Cisco Meeting Server Software, formerly Acano Conferencing Server, could allow an unauthenticated, remote attacker to conduct a persistent cross-site scripting (XSS) attack against a user of the web interface of an affected system. The vulnerability is due to improper input validation of certain parameters that are passed to an affected device via an HTTP request. An attacker could exploit this vulnerability by persuading a user to follow a malicious link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected management interface or allow the attacker to access sensitive browser-b
GHSA
GHSA-fhpm-5rg9-f5r6: Cross-site scripting (XSS) vulnerability in the web-based management interface in Cisco Meeting Server (formerly Acano Conferencing Server) 1
ghsa_unreviewed·2022-05-17
CVE-2016-1451 [MEDIUM] CWE-79 GHSA-fhpm-5rg9-f5r6: Cross-site scripting (XSS) vulnerability in the web-based management interface in Cisco Meeting Server (formerly Acano Conferencing Server) 1
Cross-site scripting (XSS) vulnerability in the web-based management interface in Cisco Meeting Server (formerly Acano Conferencing Server) 1.7 through 1.9 allows remote attackers to inject arbitrary web script or HTML via crafted parameters, aka Bug ID CSCva19922.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2016-07-15
Published