ID

VAR-201707-0079


CVE

CVE-2015-0674


TITLE

Cisco Cloud Web Security Vulnerable to cross-site scripting

Trust: 0.8

sources: JVNDB: JVNDB-2015-007663

DESCRIPTION

Cross-site scripting (XSS) vulnerability in the Alert Service of Cisco Cloud Web Security base revision allows remote attackers to inject arbitrary web script or HTML via unspecified parameters. Alert Service is one of the early warning services

Trust: 1.71

sources: NVD: CVE-2015-0674 // JVNDB: JVNDB-2015-007663 // VULHUB: VHN-78620

AFFECTED PRODUCTS

vendor:ciscomodel:cloud web securityscope:eqversion: -

Trust: 1.6

vendor:ciscomodel:cloud web securityscope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2015-007663 // CNNVD: CNNVD-201707-1245 // NVD: CVE-2015-0674

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2015-0674
value: MEDIUM

Trust: 1.0

NVD: CVE-2015-0674
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201707-1245
value: MEDIUM

Trust: 0.6

VULHUB: VHN-78620
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2015-0674
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-78620
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2015-0674
baseSeverity: MEDIUM
baseScore: 6.1
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: CHANGED
confidentialityImpact: LOW
integrityImpact: LOW
availabilityImpact: NONE
exploitabilityScore: 2.8
impactScore: 2.7
version: 3.0

Trust: 1.8

sources: VULHUB: VHN-78620 // JVNDB: JVNDB-2015-007663 // CNNVD: CNNVD-201707-1245 // NVD: CVE-2015-0674

PROBLEMTYPE DATA

problemtype:CWE-79

Trust: 1.9

sources: VULHUB: VHN-78620 // JVNDB: JVNDB-2015-007663 // NVD: CVE-2015-0674

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201707-1245

TYPE

XSS

Trust: 0.6

sources: CNNVD: CNNVD-201707-1245

CONFIGURATIONS

sources: JVNDB: JVNDB-2015-007663

PATCH

title:38058url:https://tools.cisco.com/security/center/viewAlert.x?alertId=38058

Trust: 0.8

title:Cisco Cloud Web Security Alert Service Fixes for cross-site scripting vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=72065

Trust: 0.6

sources: JVNDB: JVNDB-2015-007663 // CNNVD: CNNVD-201707-1245

EXTERNAL IDS

db:NVDid:CVE-2015-0674

Trust: 2.5

db:JVNDBid:JVNDB-2015-007663

Trust: 0.8

db:CNNVDid:CNNVD-201707-1245

Trust: 0.7

db:VULHUBid:VHN-78620

Trust: 0.1

sources: VULHUB: VHN-78620 // JVNDB: JVNDB-2015-007663 // CNNVD: CNNVD-201707-1245 // NVD: CVE-2015-0674

REFERENCES

url:https://tools.cisco.com/security/center/viewalert.x?alertid=38058

Trust: 1.7

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2015-0674

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2015-0674

Trust: 0.8

sources: VULHUB: VHN-78620 // JVNDB: JVNDB-2015-007663 // CNNVD: CNNVD-201707-1245 // NVD: CVE-2015-0674

SOURCES

db:VULHUBid:VHN-78620
db:JVNDBid:JVNDB-2015-007663
db:CNNVDid:CNNVD-201707-1245
db:NVDid:CVE-2015-0674

LAST UPDATE DATE

2025-04-20T23:30:59.350000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-78620date:2017-07-31T00:00:00
db:JVNDBid:JVNDB-2015-007663date:2017-08-28T00:00:00
db:CNNVDid:CNNVD-201707-1245date:2017-07-26T00:00:00
db:NVDid:CVE-2015-0674date:2025-04-20T01:37:25.860

SOURCES RELEASE DATE

db:VULHUBid:VHN-78620date:2017-07-25T00:00:00
db:JVNDBid:JVNDB-2015-007663date:2017-08-28T00:00:00
db:CNNVDid:CNNVD-201707-1245date:2017-07-26T00:00:00
db:NVDid:CVE-2015-0674date:2017-07-25T18:29:00.180