CVE-2015-6434

MEDIUM

Cisco Prime Infrastructure - Cross-Site Scripting via IFRAME Element

Title source: llm
STIX 2.1

Description

Cisco Prime Infrastructure does not properly restrict use of IFRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks and unspecified other attacks via a crafted web site, related to a "cross-frame scripting (XFS)" issue, aka Bug ID CSCux64856.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1034582

Scores

CVSS v3 6.1
EPSS 0.0088
EPSS Percentile 55.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
cisco/prime_infrastructure 2.2\(2\)
Published Jan 08, 2016
Tracked Since Feb 18, 2026