First published: Wed Jan 08 2014(Updated: )
Cross-site scripting (XSS) vulnerability in the Mappings page in Cisco Context Directory Agent (CDA) allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCuj45358.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Context Directory Agent |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2014-0652 is categorized as medium due to its potential to allow remote attackers to perform cross-site scripting attacks.
To fix CVE-2014-0652, users should update their Cisco Context Directory Agent to the latest version recommended by Cisco.
CVE-2014-0652 affects the Cisco Context Directory Agent across all versions.
CVE-2014-0652 enables cross-site scripting (XSS) attacks, allowing attackers to inject arbitrary web scripts or HTML.
Remote attackers can exploit CVE-2014-0652 by using crafted URLs to inject malicious scripts.