CVE-2015-6356: XSS
Published Nov 4, 2015
·Updated
Cross-site scripting (XSS) vulnerability in the WeChat page in Cisco Social Miner 10.0(1) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CSCuw60212.
Affected Software
1 affected component
Cisco SocialMiner=10.0\(1\)
Event History
Nov 4, 2015
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-6356?
CVE-2015-6356 has been classified with a medium severity rating due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2015-6356?
To fix CVE-2015-6356, upgrade to Cisco Social Miner version 10.0(2) or later where the vulnerability is addressed.
3
What type of vulnerability is CVE-2015-6356?
CVE-2015-6356 is a cross-site scripting (XSS) vulnerability that allows for the injection of arbitrary web scripts or HTML.
4
Who is affected by CVE-2015-6356?
CVE-2015-6356 affects users of Cisco Social Miner version 10.0(1).
5
Can I exploit CVE-2015-6356 remotely?
Yes, CVE-2015-6356 can be exploited remotely by attackers to execute malicious scripts in the context of a user's session.