ID

VAR-201309-0438


CVE

CVE-2013-5500


TITLE

Cisco MediaSense of oraadmin Service page cross-site scripting vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2013-004272

DESCRIPTION

Multiple cross-site scripting (XSS) vulnerabilities in the oraadmin service page in Cisco MediaSense allow remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug IDs CSCuj23320, CSCuj23324, CSCuj23333, and CSCuj23338. Cisco MediaSense of oraadmin The service page contains a cross-site scripting vulnerability. An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks. These issues are being tracked by Cisco Bug ID CSCuj23320, CSCuj23324, CSCuj23333 and CSCuj23338. Cisco MediaSense is a set of network-based scalable recording platform of Cisco (Cisco). The platform can be used to record speech and video, etc

Trust: 1.98

sources: NVD: CVE-2013-5500 // JVNDB: JVNDB-2013-004272 // BID: 62575 // VULHUB: VHN-65502

AFFECTED PRODUCTS

vendor:ciscomodel:mediasensescope:eqversion: -

Trust: 1.6

vendor:ciscomodel:mediasensescope:lteversion:9.1(1)

Trust: 0.8

sources: JVNDB: JVNDB-2013-004272 // CNNVD: CNNVD-201309-359 // NVD: CVE-2013-5500

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2013-5500
value: MEDIUM

Trust: 1.0

NVD: CVE-2013-5500
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201309-359
value: MEDIUM

Trust: 0.6

VULHUB: VHN-65502
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2013-5500
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-65502
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-65502 // JVNDB: JVNDB-2013-004272 // CNNVD: CNNVD-201309-359 // NVD: CVE-2013-5500

PROBLEMTYPE DATA

problemtype:CWE-79

Trust: 1.9

sources: VULHUB: VHN-65502 // JVNDB: JVNDB-2013-004272 // NVD: CVE-2013-5500

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201309-359

TYPE

XSS

Trust: 0.6

sources: CNNVD: CNNVD-201309-359

CONFIGURATIONS

sources: JVNDB: JVNDB-2013-004272

PATCH

title:Multiple Cisco MediaSense oraadmin Cross-Site Scripting Vulnerabilitiesurl:http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-5500

Trust: 0.8

title:30926url:http://tools.cisco.com/security/center/viewAlert.x?alertId=30926

Trust: 0.8

sources: JVNDB: JVNDB-2013-004272

EXTERNAL IDS

db:NVDid:CVE-2013-5500

Trust: 2.8

db:BIDid:62575

Trust: 1.4

db:SECTRACKid:1029064

Trust: 1.1

db:JVNDBid:JVNDB-2013-004272

Trust: 0.8

db:CNNVDid:CNNVD-201309-359

Trust: 0.7

db:CISCOid:20130919 MULTIPLE CISCO MEDIASENSE ORAADMIN CROSS-SITE SCRIPTING VULNERABILITIES

Trust: 0.6

db:VULHUBid:VHN-65502

Trust: 0.1

sources: VULHUB: VHN-65502 // BID: 62575 // JVNDB: JVNDB-2013-004272 // CNNVD: CNNVD-201309-359 // NVD: CVE-2013-5500

REFERENCES

url:http://tools.cisco.com/security/center/content/ciscosecuritynotice/cve-2013-5500

Trust: 1.7

url:http://www.securityfocus.com/bid/62575

Trust: 1.1

url:http://www.securitytracker.com/id/1029064

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2013-5500

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2013-5500

Trust: 0.8

sources: VULHUB: VHN-65502 // JVNDB: JVNDB-2013-004272 // CNNVD: CNNVD-201309-359 // NVD: CVE-2013-5500

CREDITS

Cisco

Trust: 0.3

sources: BID: 62575

SOURCES

db:VULHUBid:VHN-65502
db:BIDid:62575
db:JVNDBid:JVNDB-2013-004272
db:CNNVDid:CNNVD-201309-359
db:NVDid:CVE-2013-5500

LAST UPDATE DATE

2024-11-23T22:27:23.134000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-65502date:2013-10-02T00:00:00
db:BIDid:62575date:2013-09-25T00:13:00
db:JVNDBid:JVNDB-2013-004272date:2013-09-25T00:00:00
db:CNNVDid:CNNVD-201309-359date:2013-09-23T00:00:00
db:NVDid:CVE-2013-5500date:2024-11-21T01:57:35.673

SOURCES RELEASE DATE

db:VULHUBid:VHN-65502date:2013-09-20T00:00:00
db:BIDid:62575date:2013-09-19T00:00:00
db:JVNDBid:JVNDB-2013-004272date:2013-09-25T00:00:00
db:CNNVDid:CNNVD-201309-359date:2013-09-23T00:00:00
db:NVDid:CVE-2013-5500date:2013-09-20T16:55:07.787