Lucene search

K
cveCiscoCVE-2014-0670
HistoryJan 22, 2014 - 5:22 a.m.

CVE-2014-0670

2014-01-2205:22:20
CWE-79
cisco
web.nvd.nist.gov
35
cisco
mediasense
xss
vulnerability
cve-2014-0670
nvd
cisco security advisory

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.9

Confidence

High

EPSS

0.002

Percentile

58.9%

Cross-site scripting (XSS) vulnerability in the Search and Play interface in Cisco MediaSense allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCum16686.

Affected configurations

Nvd
Node
ciscomediasenseMatch-
VendorProductVersionCPE
ciscomediasense-cpe:2.3:a:cisco:mediasense:-:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.9

Confidence

High

EPSS

0.002

Percentile

58.9%

Related for CVE-2014-0670