CVE-2016-6425
published 2016-10-06CVE-2016-6425: Cross-site scripting (XSS) vulnerability in Cisco Unified Intelligence Center (CUIC) 8.5.4 through 9.1(1), as used in Unified Contact Center Express 10.0(1)…
PriorityP424medium6.1CVSS 3.0
AVNACLPRNUIRSCCLILAN
EPSS
1.01%
59.5th percentile
Cross-site scripting (XSS) vulnerability in Cisco Unified Intelligence Center (CUIC) 8.5.4 through 9.1(1), as used in Unified Contact Center Express 10.0(1) through 11.0(1), allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug IDs CSCuy75020 and CSCuy81652.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_contact_center_express | — | — |
| cisco | unified_contact_center_express | — | — |
| cisco | unified_contact_center_express | — | — |
| cisco | unified_contact_center_express | — | — |
| cisco | unified_intelligence_center | — | — |
| cisco | unified_intelligence_center | — | — |
| cisco | unified_intelligence_center | — | — |
| cisco | unified_intelligence_center | — | — |
CVSS provenance
nvdv3.06.1MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_cisco4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-984x-4wwc-f3w9: Cross-site scripting (XSS) vulnerability in Cisco Unified Intelligence Center (CUIC) 8
ghsa_unreviewed·2022-05-17
CVE-2016-6425 [MEDIUM] CWE-79 GHSA-984x-4wwc-f3w9: Cross-site scripting (XSS) vulnerability in Cisco Unified Intelligence Center (CUIC) 8
Cross-site scripting (XSS) vulnerability in Cisco Unified Intelligence Center (CUIC) 8.5.4 through 9.1(1), as used in Unified Contact Center Express 10.0(1) through 11.0(1), allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug IDs CSCuy75020 and CSCuy81652.
Cisco
Cisco Unified Intelligence Center (CUIC) Software Cross-Site Scripting Vulnerability
vendor_cisco·2016-10-05·CVSS 4.3
CVE-2016-6425 [MEDIUM] CWE-79 Cisco Unified Intelligence Center (CUIC) Software Cross-Site Scripting Vulnerability
Cisco Unified Intelligence Center (CUIC) Software Cross-Site Scripting Vulnerability
A vulnerability in the HTTP web-based management interface of Cisco Unified Intelligence Center (CUIC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of the affected system.
The vulnerability is due to insufficient input validation of a user-supplied value. An attacker could exploit this vulnerability by convincing a user to click a specific link. A successful exploit could allow the attacker to submit arbitrary requests to the affected system via a web browser with the privileges of the user.
Additional information about XSS attacks and potential mitigations can be found at:
http://www.cisco.com/en/US/products
Cisco
Cisco Unified Intelligence Center (CUIC) Software Cross-Site Scripting Vulnerability
vendor_cisco
CVE-2016-6425 Cisco Unified Intelligence Center (CUIC) Software Cross-Site Scripting Vulnerability
CVE-2016-6425: Cisco Unified Intelligence Center (CUIC) Software Cross-Site Scripting Vulnerability
A vulnerability in the HTTP web-based management interface of Cisco Unified Intelligence Center (CUIC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of the affected system. The vulnerability is due to insufficient input validation of a user-supplied value. An attacker could exploit this vulnerability by convincing a user to click a specific link. A successful exploit could allow the attacker to submit arbitrary requests to the affected system via a web browser with the privileges of the user. Additional information about XSS attacks and potential mitigations can be found at: http://www.cisco.com/en/
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161005-ucis1http://www.securityfocus.com/bid/93422http://www.securitytracker.com/id/1036951http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161005-ucis1http://www.securityfocus.com/bid/93422http://www.securitytracker.com/id/1036951
2016-10-06
Published