← Back

CVE-2016-6436

nvd nist
Published: Oct 6, 2016Modified: May 6, 2026

JSON object

Loading...
6.1
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD

Description

Cross-site scripting (XSS) vulnerability in HostScan Engine 3.0.08062 through 3.1.14018 in the Cisco Host Scan package, as used in ASA Web VPN, allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCuz14682.

Affected (22)

1 product
Hostscan Engine
Configuration A
22 vulnerable
Vulnerable SoftwareAffected Versions
Cisco
Version 3.0.08062
Version 3.0.08066
Version 3.1.01065
Version 3.1.02016
Version 3.1.02026
Version 3.1.02040
Version 3.1.02043
Version 3.1.03103
Version 3.1.03104
Version 3.1.04060
Version 3.1.04063
Version 3.1.04075
Version 3.1.04082
Version 3.1.05152
Version 3.1.05160
Version 3.1.05163
Version 3.1.05170
Version 3.1.05178
Version 3.1.05182
Version 3.1.05183
Version 3.1.06073
Version 3.1.14018

References (4)

Timeline

No history available yet.