ID

VAR-201508-0482


CVE

CVE-2015-4310


TITLE

Cisco Finesse Vulnerable to cross-site scripting

Trust: 0.8

sources: JVNDB: JVNDB-2015-004360

DESCRIPTION

Multiple cross-site scripting (XSS) vulnerabilities in Cisco Finesse 10.5(1) allow remote attackers to inject arbitrary web script or HTML via unspecified parameters in a (1) GET or (2) POST request, aka Bug IDs CSCuq82322, CSCut95853, and CSCuq73975. Cisco Finesse Contains a cross-site scripting vulnerability. An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks. This issue is being tracked by Cisco Bug IDs CSCuq82322, CSCut95853 and CSCuq73975. Cisco Finesse is a set of call center management software developed by Cisco. The software improves call center service quality, improves customer experience, and increases agent satisfaction

Trust: 2.07

sources: NVD: CVE-2015-4310 // JVNDB: JVNDB-2015-004360 // BID: 76407 // VULHUB: VHN-82271 // VULMON: CVE-2015-4310

AFFECTED PRODUCTS

vendor:ciscomodel:finessescope:eqversion:10.5\(1\)_base

Trust: 1.6

vendor:ciscomodel:finessescope:eqversion:10.5(1) base

Trust: 0.8

vendor:ciscomodel:finessescope:eqversion:10.5(1)

Trust: 0.3

sources: BID: 76407 // JVNDB: JVNDB-2015-004360 // CNNVD: CNNVD-201508-434 // NVD: CVE-2015-4310

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2015-4310
value: MEDIUM

Trust: 1.0

NVD: CVE-2015-4310
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201508-434
value: MEDIUM

Trust: 0.6

VULHUB: VHN-82271
value: MEDIUM

Trust: 0.1

VULMON: CVE-2015-4310
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2015-4310
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

VULHUB: VHN-82271
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-82271 // VULMON: CVE-2015-4310 // JVNDB: JVNDB-2015-004360 // CNNVD: CNNVD-201508-434 // NVD: CVE-2015-4310

PROBLEMTYPE DATA

problemtype:CWE-79

Trust: 1.9

sources: VULHUB: VHN-82271 // JVNDB: JVNDB-2015-004360 // NVD: CVE-2015-4310

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201508-434

TYPE

XSS

Trust: 0.6

sources: CNNVD: CNNVD-201508-434

CONFIGURATIONS

sources: JVNDB: JVNDB-2015-004360

PATCH

title:40436url:http://tools.cisco.com/security/center/viewAlert.x?alertId=40436

Trust: 0.8

sources: JVNDB: JVNDB-2015-004360

EXTERNAL IDS

db:NVDid:CVE-2015-4310

Trust: 2.9

db:BIDid:76407

Trust: 1.5

db:SECTRACKid:1033331

Trust: 1.2

db:JVNDBid:JVNDB-2015-004360

Trust: 0.8

db:CNNVDid:CNNVD-201508-434

Trust: 0.7

db:VULHUBid:VHN-82271

Trust: 0.1

db:VULMONid:CVE-2015-4310

Trust: 0.1

sources: VULHUB: VHN-82271 // VULMON: CVE-2015-4310 // BID: 76407 // JVNDB: JVNDB-2015-004360 // CNNVD: CNNVD-201508-434 // NVD: CVE-2015-4310

REFERENCES

url:http://tools.cisco.com/security/center/viewalert.x?alertid=40436

Trust: 2.1

url:http://www.securityfocus.com/bid/76407

Trust: 1.2

url:http://www.securitytracker.com/id/1033331

Trust: 1.2

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2015-4310

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2015-4310

Trust: 0.8

url:http://www.cisco.com/

Trust: 0.3

url:https://cwe.mitre.org/data/definitions/79.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

sources: VULHUB: VHN-82271 // VULMON: CVE-2015-4310 // BID: 76407 // JVNDB: JVNDB-2015-004360 // CNNVD: CNNVD-201508-434 // NVD: CVE-2015-4310

CREDITS

Cisco

Trust: 0.3

sources: BID: 76407

SOURCES

db:VULHUBid:VHN-82271
db:VULMONid:CVE-2015-4310
db:BIDid:76407
db:JVNDBid:JVNDB-2015-004360
db:CNNVDid:CNNVD-201508-434
db:NVDid:CVE-2015-4310

LAST UPDATE DATE

2024-11-23T21:54:54.804000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-82271date:2017-01-04T00:00:00
db:VULMONid:CVE-2015-4310date:2017-01-04T00:00:00
db:BIDid:76407date:2015-08-18T00:00:00
db:JVNDBid:JVNDB-2015-004360date:2015-08-25T00:00:00
db:CNNVDid:CNNVD-201508-434date:2015-08-20T00:00:00
db:NVDid:CVE-2015-4310date:2024-11-21T02:30:48.800

SOURCES RELEASE DATE

db:VULHUBid:VHN-82271date:2015-08-19T00:00:00
db:VULMONid:CVE-2015-4310date:2015-08-19T00:00:00
db:BIDid:76407date:2015-08-18T00:00:00
db:JVNDBid:JVNDB-2015-004360date:2015-08-25T00:00:00
db:CNNVDid:CNNVD-201508-434date:2015-08-20T00:00:00
db:NVDid:CVE-2015-4310date:2015-08-19T23:59:01.480