Cross-site scripting (XSS) vulnerability in CSCOnm/servlet/com.cisco.nm.help.ServerHelpEngine in the Common Services Device Center in Cisco Unified Operations Manager (CUOM) before 8.6 allows remote attackers to inject arbitrary web script or HTML via the tag parameter, aka Bug ID CSCto12712.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 01:25
Type | Values Removed | Values Added |
---|---|---|
References | () http://archives.neohapsis.com/archives/fulldisclosure/2011-05/0371.html - Exploit | |
References | () http://tools.cisco.com/security/center/viewAlert.x?alertId=23087 - | |
References | () http://www.exploit-db.com/exploits/17304 - Exploit | |
References | () http://www.senseofsecurity.com.au/advisories/SOS-11-006.pdf - Exploit, URL Repurposed | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/67524 - |
14 Feb 2024, 01:17
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) http://www.senseofsecurity.com.au/advisories/SOS-11-006.pdf - Exploit, URL Repurposed |
Information
Published : 2011-05-20 22:55
Updated : 2024-11-21 01:25
NVD link : CVE-2011-0962
Mitre link : CVE-2011-0962
CVE.ORG link : CVE-2011-0962
JSON object : View
Products Affected
cisco
- unified_operations_manager
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')