4.3
CVSSv2

CVE-2011-0961

Published: 20/05/2011 Updated: 14/02/2024
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 440
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in cwhp/device.center.do in the Help servlet in Cisco CiscoWorks Common Services 3.3 and previous versions allows remote malicious users to inject arbitrary web script or HTML via the device parameter, aka Bug ID CSCto12704.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco ciscoworks common services 2.2

cisco ciscoworks common services

cisco ciscoworks common services 3.0.6

cisco ciscoworks common services 3.0.4

cisco ciscoworks common services 3.2

cisco ciscoworks common services 1.0

cisco ciscoworks common services 3.1.1

cisco ciscoworks common services 3.0

cisco ciscoworks common services 3.1

cisco ciscoworks common services 3.0.3

cisco ciscoworks common services 3.0.5

Vendor Advisories

CiscoWorks Common Services contains a cross-site scripting vulnerability that could allow an unauthenticated, remote attacker to conduct cross-site scripting attacks The vulnerability is due to improper validation of malformed user input supplied via URL parameters to the affected application An unauthenticated, remote attacker could exploit thi ...

Exploits

Cisco Unified Operations Manager suffers from cross site scripting, remote SQL injection, and directory traversal vulnerabilities Versions 80 and 85 are affected ...
source: wwwsecurityfocuscom/bid/47902/info CiscoWorks Common Services is prone to a cross-site scripting vulnerability because the application fails to sufficiently sanitize user-supplied input Exploiting this vulnerability could allow an attacker to perform cross-site scripting attacks on unsuspecting users in the context of the affect ...
Sense of Security - Security Advisory - SOS-11-006 Release Date 18-May-2011 Last Update - Vendor Notification Date 28-Feb-2011 Product Cisco Unified Operations Manager Common Services Framework Help Servlet Common Service ...