ID

VAR-201507-0545


CVE

CVE-2015-4260


TITLE

Cisco Hosted Collaboration Solution Vulnerable to cross-site scripting

Trust: 0.8

sources: JVNDB: JVNDB-2015-003550

DESCRIPTION

Cross-site scripting (XSS) vulnerability in Cisco Hosted Collaboration Solution 10.6(1) allows remote attackers to inject arbitrary web script or HTML via a crafted value in a URL, aka Bug ID CSCuu14862. An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks. This issue is being tracked by Cisco Bug ID CSCuu14862. The solution includes products such as Cisco TelePresence, Customer Collaboration (Contact Center) and Unified Communications to support customers to use collaboration technology in public cloud, private cloud and hybrid cloud models

Trust: 1.98

sources: NVD: CVE-2015-4260 // JVNDB: JVNDB-2015-003550 // BID: 75680 // VULHUB: VHN-82221

AFFECTED PRODUCTS

vendor:ciscomodel:hosted collaboration solutionscope:eqversion:10.6\(1\)_base

Trust: 1.6

vendor:ciscomodel:hosted collaboration solutionscope:eqversion:10.6(1)

Trust: 1.1

sources: BID: 75680 // JVNDB: JVNDB-2015-003550 // CNNVD: CNNVD-201507-331 // NVD: CVE-2015-4260

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2015-4260
value: MEDIUM

Trust: 1.0

NVD: CVE-2015-4260
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201507-331
value: MEDIUM

Trust: 0.6

VULHUB: VHN-82221
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2015-4260
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-82221
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-82221 // JVNDB: JVNDB-2015-003550 // CNNVD: CNNVD-201507-331 // NVD: CVE-2015-4260

PROBLEMTYPE DATA

problemtype:CWE-79

Trust: 1.9

sources: VULHUB: VHN-82221 // JVNDB: JVNDB-2015-003550 // NVD: CVE-2015-4260

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201507-331

TYPE

XSS

Trust: 0.6

sources: CNNVD: CNNVD-201507-331

CONFIGURATIONS

sources: JVNDB: JVNDB-2015-003550

PATCH

title:39804url:http://tools.cisco.com/security/center/viewAlert.x?alertId=39804

Trust: 0.8

sources: JVNDB: JVNDB-2015-003550

EXTERNAL IDS

db:NVDid:CVE-2015-4260

Trust: 2.8

db:SECTRACKid:1032840

Trust: 1.1

db:JVNDBid:JVNDB-2015-003550

Trust: 0.8

db:CNNVDid:CNNVD-201507-331

Trust: 0.7

db:BIDid:75680

Trust: 0.4

db:VULHUBid:VHN-82221

Trust: 0.1

sources: VULHUB: VHN-82221 // BID: 75680 // JVNDB: JVNDB-2015-003550 // CNNVD: CNNVD-201507-331 // NVD: CVE-2015-4260

REFERENCES

url:http://tools.cisco.com/security/center/viewalert.x?alertid=39804

Trust: 2.0

url:http://www.securitytracker.com/id/1032840

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2015-4260

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2015-4260

Trust: 0.8

url:http://www.cisco.com/

Trust: 0.3

url:http://www.cisco.com/en/us/products/ps11363/index.html

Trust: 0.3

sources: VULHUB: VHN-82221 // BID: 75680 // JVNDB: JVNDB-2015-003550 // CNNVD: CNNVD-201507-331 // NVD: CVE-2015-4260

CREDITS

Cisco

Trust: 0.3

sources: BID: 75680

SOURCES

db:VULHUBid:VHN-82221
db:BIDid:75680
db:JVNDBid:JVNDB-2015-003550
db:CNNVDid:CNNVD-201507-331
db:NVDid:CVE-2015-4260

LAST UPDATE DATE

2024-11-23T21:54:55.766000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-82221date:2016-12-28T00:00:00
db:BIDid:75680date:2015-07-09T00:00:00
db:JVNDBid:JVNDB-2015-003550date:2015-07-14T00:00:00
db:CNNVDid:CNNVD-201507-331date:2015-07-13T00:00:00
db:NVDid:CVE-2015-4260date:2024-11-21T02:30:43.557

SOURCES RELEASE DATE

db:VULHUBid:VHN-82221date:2015-07-10T00:00:00
db:BIDid:75680date:2015-07-09T00:00:00
db:JVNDBid:JVNDB-2015-003550date:2015-07-14T00:00:00
db:CNNVDid:CNNVD-201507-331date:2015-07-13T00:00:00
db:NVDid:CVE-2015-4260date:2015-07-10T10:59:01.440