Cisco Bug: CSCul16173 - CS-MARS Query Engine is vulnerable to cross-site-scripting attacks
Aug 11, 2015
- Cisco Security Monitoring, Analysis and Response System
Known Affected Releases
Symptom: Cisco Security Monitoring, Analysis and Response System (CS-MARS) devices are affected by a Cross-Site Scripting vulnerability within the Query engine of the product. This could allow an unauthenticated, remote attacker that can convince an authenticated user to follow a malicious link or access an attacker controlled website to potentially execute arbitrary script code within the security context of the affected site. Successful exploitation could allow the attacker to steal sensitive web based information such as user cookies or other information. CS-MARS entered the End of Software Maintenance phase April 11th, 2009. Cisco Engineering will not be releasing a new version of CS-MARS that mitigates this vulnerability. Conditions: Cisco Security Monitoring, Analysis and Response System devices running any version of software are affected.
Bug details contain sensitive information and therefore require a Cisco.com account to be viewed.
Bug Details Include
- Full Description (including symptoms, conditions and workarounds)
- Known Fixed Releases
- Related Community Discussions
- Number of Related Support Cases