CVE-2015-6402
Cisco EPC3928 EDVA 5.5.10, 5.5.11, 5.7.1 - Cross-Site Scripting
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2015-6402. PoCs published by Patryk Bogdan.
AI-analyzed exploit summary This PoC demonstrates multiple vulnerabilities in Cisco EPC3928, including unauthorized command execution, XSS (stored and reflective), DoS, and information disclosure. It provides HTTP requests to exploit these flaws, confirming their validity.
Description
Cross-site scripting (XSS) vulnerability in the management interface on Cisco EPC3928 devices with EDVA 5.5.10, 5.5.11, and 5.7.1 allows remote attackers to inject arbitrary web script or HTML via an unspecified value, aka Bug ID CSCux24935.
Exploits (1)
This PoC demonstrates multiple vulnerabilities in Cisco EPC3928, including unauthorized command execution, XSS (stored and reflective), DoS, and information disclosure. It provides HTTP requests to exploit these flaws, confirming their validity.