ID

VAR-201508-0502


CVE

CVE-2015-4294


TITLE

Cisco Unified Communications Manager IM and Presence Service Vulnerable to cross-site scripting

Trust: 0.8

sources: JVNDB: JVNDB-2015-003964

DESCRIPTION

Cross-site scripting (XSS) vulnerability in Cisco IM and Presence Service before 10.5 MR1 allows remote attackers to inject arbitrary web script or HTML by constructing a crafted URL that leverages incomplete filtering of HTML elements, aka Bug ID CSCut41766. Cisco Unified Communications Manager IM and Presence Service Contains a cross-site scripting vulnerability. An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks. This issue is being tracked by Cisco Bug ID CSCut41766

Trust: 1.98

sources: NVD: CVE-2015-4294 // JVNDB: JVNDB-2015-003964 // BID: 76126 // VULHUB: VHN-82255

AFFECTED PRODUCTS

vendor:ciscomodel:unified communications manager im and presence servicescope:eqversion:10.5\(1\)

Trust: 1.6

vendor:ciscomodel:unified communications manager im and presence servicescope:eqversion:9.1\(1\)

Trust: 1.6

vendor:ciscomodel:unified communications manager im and presence servicescope:eqversion:9.0\(1\)

Trust: 1.6

vendor:ciscomodel:unified communications manager im and presence servicescope:ltversion:10.5 mr1

Trust: 0.8

vendor:ciscomodel:unified communications manager im and presence servicescope:eqversion:9.1(1)

Trust: 0.3

vendor:ciscomodel:unified communications manager im and presence servicescope:eqversion:9.0(1)

Trust: 0.3

vendor:ciscomodel:unified communications manager im and presence servicescope:eqversion:10.5(1)

Trust: 0.3

vendor:ciscomodel:unified communications manager im and presence service mr1scope:neversion:10.5

Trust: 0.3

sources: BID: 76126 // JVNDB: JVNDB-2015-003964 // CNNVD: CNNVD-201507-848 // NVD: CVE-2015-4294

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2015-4294
value: MEDIUM

Trust: 1.0

NVD: CVE-2015-4294
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201507-848
value: MEDIUM

Trust: 0.6

VULHUB: VHN-82255
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2015-4294
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-82255
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-82255 // JVNDB: JVNDB-2015-003964 // CNNVD: CNNVD-201507-848 // NVD: CVE-2015-4294

PROBLEMTYPE DATA

problemtype:CWE-79

Trust: 1.9

sources: VULHUB: VHN-82255 // JVNDB: JVNDB-2015-003964 // NVD: CVE-2015-4294

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201507-848

TYPE

XSS

Trust: 0.6

sources: CNNVD: CNNVD-201507-848

CONFIGURATIONS

sources: JVNDB: JVNDB-2015-003964

PATCH

title:40217url:http://tools.cisco.com/security/center/viewAlert.x?alertId=40217

Trust: 0.8

sources: JVNDB: JVNDB-2015-003964

EXTERNAL IDS

db:NVDid:CVE-2015-4294

Trust: 2.8

db:SECTRACKid:1033171

Trust: 1.1

db:JVNDBid:JVNDB-2015-003964

Trust: 0.8

db:CNNVDid:CNNVD-201507-848

Trust: 0.7

db:BIDid:76126

Trust: 0.4

db:VULHUBid:VHN-82255

Trust: 0.1

sources: VULHUB: VHN-82255 // BID: 76126 // JVNDB: JVNDB-2015-003964 // CNNVD: CNNVD-201507-848 // NVD: CVE-2015-4294

REFERENCES

url:http://tools.cisco.com/security/center/viewalert.x?alertid=40217

Trust: 2.0

url:http://www.securitytracker.com/id/1033171

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2015-4294

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2015-4294

Trust: 0.8

url:http://www.cisco.com/

Trust: 0.3

sources: VULHUB: VHN-82255 // BID: 76126 // JVNDB: JVNDB-2015-003964 // CNNVD: CNNVD-201507-848 // NVD: CVE-2015-4294

CREDITS

Cisco

Trust: 0.3

sources: BID: 76126

SOURCES

db:VULHUBid:VHN-82255
db:BIDid:76126
db:JVNDBid:JVNDB-2015-003964
db:CNNVDid:CNNVD-201507-848
db:NVDid:CVE-2015-4294

LAST UPDATE DATE

2024-11-23T22:45:56.514000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-82255date:2015-08-21T00:00:00
db:BIDid:76126date:2015-07-30T00:00:00
db:JVNDBid:JVNDB-2015-003964date:2015-08-04T00:00:00
db:CNNVDid:CNNVD-201507-848date:2015-08-03T00:00:00
db:NVDid:CVE-2015-4294date:2024-11-21T02:30:47.170

SOURCES RELEASE DATE

db:VULHUBid:VHN-82255date:2015-08-01T00:00:00
db:BIDid:76126date:2015-07-30T00:00:00
db:JVNDBid:JVNDB-2015-003964date:2015-08-04T00:00:00
db:CNNVDid:CNNVD-201507-848date:2015-07-31T00:00:00
db:NVDid:CVE-2015-4294date:2015-08-01T01:59:17.847