Show filters
125 Total Results
Displaying 101-110 of 125
Sort by:
Attacker Value
Unknown

CVE-2015-4198

Disclosure Date: June 20, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the web framework on Cisco Web Security Appliance (WSA) devices with software 8.5.0-497 allows remote attackers to inject arbitrary web script or HTML via an unspecified HTTP header, aka Bug ID CSCuu24409.
0
Attacker Value
Unknown

CVE-2015-0738

Disclosure Date: May 17, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Web Tracking Report page on Cisco Web Security Appliance (WSA) devices 8.5.0-497 allows remote attackers to inject arbitrary web script or HTML via an unspecified field, aka Bug ID CSCuu16008.
0
Attacker Value
Unknown

CVE-2015-0698

Disclosure Date: April 15, 2015 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in filter search forms in admin web pages on Cisco Web Security Appliance (WSA) devices with software 8.5.0-497 allow remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCut39213.
0
Attacker Value
Unknown

CVE-2015-0693

Disclosure Date: April 15, 2015 (last updated October 05, 2023)
Cisco Web Security Appliance (WSA) devices with software 8.5.0-ise-147 do not properly restrict use of the pickle Python module during certain tunnel-status checks, which allows local users to execute arbitrary Python code and gain privileges via a crafted pickle file, aka Bug ID CSCut39259.
0
Attacker Value
Unknown

CVE-2015-0692

Disclosure Date: April 11, 2015 (last updated October 05, 2023)
Cisco Web Security Appliance (WSA) devices with software 8.5.0-ise-147 do not properly restrict use of the pickle Python module during certain tunnel-status checks, which allows local users to execute arbitrary Python code and gain privileges via crafted serialized objects, aka Bug ID CSCut39230.
0
Attacker Value
Unknown

CVE-2015-0624

Disclosure Date: February 21, 2015 (last updated October 05, 2023)
The web framework in Cisco AsyncOS on Email Security Appliance (ESA), Content Security Management Appliance (SMA), and Web Security Appliance (WSA) devices allows remote attackers to trigger redirects via a crafted HTTP header, aka Bug IDs CSCur44412, CSCur44415, CSCur89630, CSCur89636, CSCur89633, and CSCur89639.
0
Attacker Value
Unknown

CVE-2015-0628

Disclosure Date: February 20, 2015 (last updated October 05, 2023)
The proxy engine on Cisco Web Security Appliance (WSA) devices allows remote attackers to bypass intended proxying restrictions via a malformed HTTP method, aka Bug ID CSCus79174.
0
Attacker Value
Unknown

CVE-2015-0623

Disclosure Date: February 19, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Administrator report page on Cisco Web Security Appliance (WSA) devices allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CSCus40627.
0
Attacker Value
Unknown

CVE-2014-8510

Disclosure Date: November 07, 2014 (last updated October 05, 2023)
The AdminUI in Trend Micro InterScan Web Security Virtual Appliance (IWSVA) before 6.0 HF build 1244 allows remote authenticated users to read arbitrary files via vectors related to configuration input when saving filters.
0
Attacker Value
Unknown

CVE-2014-6079

Disclosure Date: October 03, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Local Management Interface in IBM Security Access Manager for Web 7.x before 7.0.0-ISS-WGA-IF0009 and 8.x before 8.0.0-ISS-WGA-FP0005, and Security Access Manager for Mobile 8.x before 8.0.0-ISS-ISAM-FP0005, allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
0