First published: Sun Dec 13 2015(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in Cisco Emergency Responder 10.5(1a) allow remote attackers to inject arbitrary web script or HTML via unspecified fields, aka Bug ID CSCuv25547.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Emergency Responder | =10.5\(1a\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-6400 has been classified as having a high severity due to its potential for remote exploitation.
To mitigate CVE-2015-6400, upgrade to Cisco Emergency Responder version 10.5(1b) or later.
CVE-2015-6400 can be exploited to perform cross-site scripting (XSS) attacks, allowing injection of arbitrary web scripts.
CVE-2015-6400 specifically affects Cisco Emergency Responder version 10.5(1a).
Check your Cisco Emergency Responder version; if it is 10.5(1a), your system is vulnerable to CVE-2015-6400.