CVE-2016-6436

Cross-site scripting (XSS) vulnerability in HostScan Engine 3.0.08062 through 3.1.14018 in the Cisco Host Scan package, as used in ASA Web VPN, allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCuz14682.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.1 MEDIUM
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
ciscoCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 48%
VendorProductVersion
ciscohostscan_engine
3.0.08062
ciscohostscan_engine
3.0.08066
ciscohostscan_engine
3.1.01065
ciscohostscan_engine
3.1.02016
ciscohostscan_engine
3.1.02026
ciscohostscan_engine
3.1.02040
ciscohostscan_engine
3.1.02043
ciscohostscan_engine
3.1.03103
ciscohostscan_engine
3.1.03104
ciscohostscan_engine
3.1.04060
ciscohostscan_engine
3.1.04063
ciscohostscan_engine
3.1.04075
ciscohostscan_engine
3.1.04082
ciscohostscan_engine
3.1.05152
ciscohostscan_engine
3.1.05160
ciscohostscan_engine
3.1.05163
ciscohostscan_engine
3.1.05170
ciscohostscan_engine
3.1.05178
ciscohostscan_engine
3.1.05182
ciscohostscan_engine
3.1.05183
ciscohostscan_engine
3.1.06073
ciscohostscan_engine
3.1.14018
𝑥
= Vulnerable software versions