ID

VAR-201511-0011


CVE

CVE-2015-6356


TITLE

Cisco SocialMiner of WeChat Page cross-site scripting vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2015-005733

DESCRIPTION

Cross-site scripting (XSS) vulnerability in the WeChat page in Cisco Social Miner 10.0(1) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CSCuw60212. Cisco SocialMiner of WeChat The page contains a cross-site scripting vulnerability. Vendors have confirmed this vulnerability Bug ID CSCuw60212 It is released as.By any third party Web Script or HTML May be inserted. An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks. This issue is being tracked by Cisco Bug ID CSCuw60212. Cisco SocialMiner is a set of social media call center solutions from Cisco. The solution supports social media monitoring and analysis capabilities

Trust: 1.98

sources: NVD: CVE-2015-6356 // JVNDB: JVNDB-2015-005733 // BID: 77418 // VULHUB: VHN-84317

AFFECTED PRODUCTS

vendor:ciscomodel:socialminerscope:eqversion:10.0\(1\)

Trust: 1.6

vendor:ciscomodel:socialminerscope:eqversion:10.0(1)

Trust: 1.1

sources: BID: 77418 // JVNDB: JVNDB-2015-005733 // CNNVD: CNNVD-201511-058 // NVD: CVE-2015-6356

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2015-6356
value: MEDIUM

Trust: 1.0

NVD: CVE-2015-6356
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201511-058
value: MEDIUM

Trust: 0.6

VULHUB: VHN-84317
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2015-6356
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-84317
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-84317 // JVNDB: JVNDB-2015-005733 // CNNVD: CNNVD-201511-058 // NVD: CVE-2015-6356

PROBLEMTYPE DATA

problemtype:CWE-79

Trust: 1.9

sources: VULHUB: VHN-84317 // JVNDB: JVNDB-2015-005733 // NVD: CVE-2015-6356

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201511-058

TYPE

XSS

Trust: 0.6

sources: CNNVD: CNNVD-201511-058

CONFIGURATIONS

sources: JVNDB: JVNDB-2015-005733

PATCH

title:cisco-sa-20151103-csmurl:http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151103-csm

Trust: 0.8

title:Cisco SocialMiner WeChat Fixes for page cross-site scripting vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=58567

Trust: 0.6

sources: JVNDB: JVNDB-2015-005733 // CNNVD: CNNVD-201511-058

EXTERNAL IDS

db:NVDid:CVE-2015-6356

Trust: 2.8

db:SECTRACKid:1034048

Trust: 1.1

db:JVNDBid:JVNDB-2015-005733

Trust: 0.8

db:CNNVDid:CNNVD-201511-058

Trust: 0.7

db:BIDid:77418

Trust: 0.4

db:VULHUBid:VHN-84317

Trust: 0.1

sources: VULHUB: VHN-84317 // BID: 77418 // JVNDB: JVNDB-2015-005733 // CNNVD: CNNVD-201511-058 // NVD: CVE-2015-6356

REFERENCES

url:http://tools.cisco.com/security/center/content/ciscosecurityadvisory/cisco-sa-20151103-csm

Trust: 2.0

url:http://www.securitytracker.com/id/1034048

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2015-6356

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2015-6356

Trust: 0.8

url:http://www.cisco.com/en/us/products/ps11349/index.html

Trust: 0.3

sources: VULHUB: VHN-84317 // BID: 77418 // JVNDB: JVNDB-2015-005733 // CNNVD: CNNVD-201511-058 // NVD: CVE-2015-6356

CREDITS

Cisco

Trust: 0.3

sources: BID: 77418

SOURCES

db:VULHUBid:VHN-84317
db:BIDid:77418
db:JVNDBid:JVNDB-2015-005733
db:CNNVDid:CNNVD-201511-058
db:NVDid:CVE-2015-6356

LAST UPDATE DATE

2024-11-23T22:34:56.103000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-84317date:2016-12-07T00:00:00
db:BIDid:77418date:2015-11-03T00:00:00
db:JVNDBid:JVNDB-2015-005733date:2015-11-05T00:00:00
db:CNNVDid:CNNVD-201511-058date:2015-11-05T00:00:00
db:NVDid:CVE-2015-6356date:2024-11-21T02:34:50.707

SOURCES RELEASE DATE

db:VULHUBid:VHN-84317date:2015-11-04T00:00:00
db:BIDid:77418date:2015-11-03T00:00:00
db:JVNDBid:JVNDB-2015-005733date:2015-11-05T00:00:00
db:CNNVDid:CNNVD-201511-058date:2015-11-05T00:00:00
db:NVDid:CVE-2015-6356date:2015-11-04T03:59:10.577