Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.106601
Categoría:CISCO
Título:Cisco Firepower Management Center Web Framework Cross-Site Scripting Vulnerability
Resumen:A vulnerability in the web framework of Cisco Firepower Management Center; could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of; the web interface.
Descripción:Summary:
A vulnerability in the web framework of Cisco Firepower Management Center
could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of
the web interface.

Vulnerability Insight:
The vulnerability occurs because the affected software fails to perform
sufficient validation and sanitization of user-supplied input when processing crafted URLs. An authenticated,
remote attacker could exploit the vulnerability by convincing a user to follow a malicious link.

Vulnerability Impact:
Successful exploitation could allow the attacker to execute arbitrary script
code in the context of the affected site and allow the attacker to access sensitive browser-based information.

Solution:
See the referenced vendor advisory for a solution.

CVSS Score:
3.5

CVSS Vector:
AV:N/AC:M/Au:S/C:N/I:P/A:N

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2017-3847
BugTraq ID: 96253
http://www.securityfocus.com/bid/96253
CopyrightCopyright (C) 2017 Greenbone AG

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.