First published: Wed Nov 06 2013(Updated: )
Cross-site scripting (XSS) vulnerability in Query/NewQueryResult.jsp in Cisco Security Monitoring, Analysis and Response System (CS-MARS) allows remote attackers to inject arbitrary web script or HTML via the isnowLatency parameter, aka Bug ID CSCul16173.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Security Monitoring Analysis and Response System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-5563 is classified as a medium severity vulnerability due to its potential for exploitation via cross-site scripting.
To mitigate CVE-2013-5563, it is recommended to apply the latest patches provided by Cisco for the Security Monitoring, Analysis and Response System.
CVE-2013-5563 affects versions of Cisco Security Monitoring, Analysis and Response System (CS-MARS) before the release of fixed versions.
CVE-2013-5563 is a cross-site scripting (XSS) vulnerability that allows remote attackers to inject malicious scripts.
Yes, CVE-2013-5563 can be exploited remotely by sending crafted requests to the vulnerable system.