CVE-2015-0738: XSS
Published May 17, 2015
·Updated
Cross-site scripting (XSS) vulnerability in the Web Tracking Report page on Cisco Web Security Appliance (WSA) devices 8.5.0-497 allows remote attackers to inject arbitrary web script or HTML via an unspecified field, aka Bug ID CSCuu16008.
Affected Software
1 affected component
Cisco Web Security Appliance=8.5.0-497
Event History
May 17, 2015
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-0738?
CVE-2015-0738 is considered a high severity cross-site scripting vulnerability.
2
How do I fix CVE-2015-0738?
To fix CVE-2015-0738, upgrade your Cisco Web Security Appliance to version 8.5.0-500 or later.
3
What systems are affected by CVE-2015-0738?
CVE-2015-0738 affects Cisco Web Security Appliance versions 8.5.0-497.
4
What kind of attack does CVE-2015-0738 enable?
CVE-2015-0738 enables remote attackers to inject arbitrary web scripts or HTML into the Web Tracking Report page.
5
Is authentication required to exploit CVE-2015-0738?
No, authentication is not required to exploit CVE-2015-0738, making it especially dangerous.