First published: Sun May 17 2015(Updated: )
Cross-site scripting (XSS) vulnerability in the Web Tracking Report page on Cisco Web Security Appliance (WSA) devices 8.5.0-497 allows remote attackers to inject arbitrary web script or HTML via an unspecified field, aka Bug ID CSCuu16008.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Web Security Appliance | =8.5.0-497 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-0738 is considered a high severity cross-site scripting vulnerability.
To fix CVE-2015-0738, upgrade your Cisco Web Security Appliance to version 8.5.0-500 or later.
CVE-2015-0738 affects Cisco Web Security Appliance versions 8.5.0-497.
CVE-2015-0738 enables remote attackers to inject arbitrary web scripts or HTML into the Web Tracking Report page.
No, authentication is not required to exploit CVE-2015-0738, making it especially dangerous.