CVE-2015-6400: XSS
Published Dec 13, 2015
·Updated
Multiple cross-site scripting (XSS) vulnerabilities in Cisco Emergency Responder 10.5(1a) allow remote attackers to inject arbitrary web script or HTML via unspecified fields, aka Bug ID CSCuv25547.
Affected Software
1 affected component
Cisco Emergency Responder=10.5\(1a\)
Event History
Dec 13, 2015
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-6400?
CVE-2015-6400 has been classified as having a high severity due to its potential for remote exploitation.
2
How do I fix CVE-2015-6400?
To mitigate CVE-2015-6400, upgrade to Cisco Emergency Responder version 10.5(1b) or later.
3
What types of attacks are possible with CVE-2015-6400?
CVE-2015-6400 can be exploited to perform cross-site scripting (XSS) attacks, allowing injection of arbitrary web scripts.
4
Which software versions are affected by CVE-2015-6400?
CVE-2015-6400 specifically affects Cisco Emergency Responder version 10.5(1a).
5
How can I determine if my system is vulnerable to CVE-2015-6400?
Check your Cisco Emergency Responder version; if it is 10.5(1a), your system is vulnerable to CVE-2015-6400.