Show filters
340 Total Results
Displaying 291-300 of 340
Sort by:
Attacker Value
Unknown
CVE-2015-0768
Disclosure Date: June 12, 2015 (last updated October 05, 2023)
The Device Work Center (DWC) component in Cisco Prime Network Control System (NCS) 2.1(0.0.85), 2.2(0.0.58), and 2.2(0.0.69) does not properly implement AAA roles, which allows remote authenticated users to bypass intended access restrictions and execute commands via a login session, aka Bug ID CSCur27371.
0
Attacker Value
Unknown
CVE-2015-0666
Disclosure Date: April 03, 2015 (last updated October 05, 2023)
Directory traversal vulnerability in the fmserver servlet in Cisco Prime Data Center Network Manager (DCNM) before 7.1(1) allows remote attackers to read arbitrary files via a crafted pathname, aka Bug ID CSCus00241.
0
Attacker Value
Unknown
CVE-2015-0594
Disclosure Date: February 27, 2015 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in the help pages in Cisco Common Services, as used in Cisco Prime LAN Management Solution (LMS) and Cisco Security Manager, allow remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug IDs CSCuq54654 and CSCun18263.
0
Attacker Value
Unknown
CVE-2014-3365
Disclosure Date: February 12, 2015 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Cisco Prime Security Manager (PRSM) 9.2(.1-2) and earlier allow remote attackers to inject arbitrary web script or HTML via crafted input to the (1) Dashboard or (2) Configure Realm page, aka Bug ID CSCuo94808.
0
Attacker Value
Unknown
CVE-2014-2153
Disclosure Date: February 12, 2015 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in INSERT pages in Cisco Prime Infrastructure allow remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug ID CSCun21869.
0
Attacker Value
Unknown
CVE-2014-2147
Disclosure Date: February 12, 2015 (last updated October 05, 2023)
The web interface in Cisco Prime Infrastructure 2.1 and earlier does not properly restrict use of IFRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks and unspecified other attacks via a crafted web site, related to a "cross-frame scripting (XFS)" issue, aka Bug ID CSCuj42444.
0
Attacker Value
Unknown
CVE-2014-2152
Disclosure Date: February 12, 2015 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in the INSERT page in Cisco Prime Infrastructure (PI) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCun21868.
0
Attacker Value
Unknown
CVE-2015-0581
Disclosure Date: January 28, 2015 (last updated October 05, 2023)
The XML parser in Cisco Prime Service Catalog before 10.1 allows remote authenticated users to read arbitrary files or cause a denial of service (CPU and memory consumption) via an external entity declaration in conjunction with an entity reference, as demonstrated by reading private keys, related to an XML External Entity (XXE) issue, aka Bug ID CSCup92880.
0
Attacker Value
Unknown
CVE-2014-8007
Disclosure Date: December 20, 2014 (last updated October 05, 2023)
Cisco Prime Infrastructure allows remote authenticated users to read device-discovery passwords by examining the HTML source code of the Quick Discovery options page, aka Bug ID CSCum00019.
0
Attacker Value
Unknown
CVE-2014-3364
Disclosure Date: December 13, 2014 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in the web framework in Cisco Prime Security Manager (aka PRSM) 9.2.1-2 and earlier allow remote attackers to inject arbitrary web script or HTML via a (1) Access Policies or (2) Device Summary Dashboard parameter, aka Bug ID CSCuq80661.
0