CVE-2017-6782
Summary
| CVE | CVE-2017-6782 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-08-17 20:29:00 UTC |
| Updated | 2017-08-25 10:51:00 UTC |
| Description | A vulnerability in the administrative web interface of Cisco Prime Infrastructure could allow an authenticated, remote attacker to modify a page in the web interface of the affected application. The vulnerability is due to improper sanitization of parameter values by the affected application. An attacker could exploit this vulnerability by injecting malicious code into an affected parameter and persuading a user to access a web page that triggers the rendering of the injected code. Cisco Bug IDs: CSCve47074. Known Affected Releases: 3.2(0.0). |
Risk And Classification
Problem Types: CWE-94
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Cisco | Prime Infrastructure | 3.2(0.0) | All | All | All |
| Application | Cisco | Prime Infrastructure | 3.2\(0.0\) | All | All | All |
| Application | Cisco | Prime Infrastructure | 3.2\(0.0\) | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Cisco Prime Infrastructure Flaw Lets Remote Users Inject HTML to Modify a Page on the Target System - SecurityTracker | SECTRACK | www.securitytracker.com | Third Party Advisory, VDB Entry |
| Cisco Prime Infrastructure CVE-2017-6782 HTML Injection Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Cisco Prime Infrastructure HTML Injection Vulnerability | CISCO | tools.cisco.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.