Vulnerability Bulletins

Cisco FireSIGHT Management Center DOM-Based Cross-Site Scripting Vulnerability

   
Affected software Cisco
 
Cisco FireSIGHT Management Center (MC) contains a DOM-based cross-site scripting vulnerability (XSS) in the management page. An unauthenticated, remote attacker could persuade a user to perform a malicious action, allowing the attacker to perform a XSS attack.The vulnerability is due to mishandling of certain attributes that are processed in cookies passed as part of a request. A successful exploit could allow the attacker to execute arbitrary script or HTML code on the users browser in the

More info:

http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160115-fmc1?vs_f=Cisco%20Security%20Advisory&vs_cat=Security%20Intelligence&vs_type=RSS&vs_p=Cisco%20FireSIGHT%20Management%20Center%20DOM-Based%20Cross-Site%20Scripting%