Multiple Cross-Site Scripting Vulnerabilities in Cisco Unified Operations Manager
CVE-2011-0959

Currently unrated

Key Information:

Vendor
Cisco
Vendor
CVE Published:
20 May 2011

Summary

Multiple cross-site scripting (XSS) vulnerabilities exist in Cisco Unified Operations Manager prior to version 8.6. These vulnerabilities allow remote attackers to inject arbitrary web scripts or HTML into affected components. Exploitation can occur through various parameters such as 'extn' in iptm/advancedfind.do, 'deviceInstanceName' in iptm/ddv.do, and more critical points throughout the application. Successful exploit enables attackers to execute malicious scripts in the context of the user's browser, potentially compromising sensitive data and session information.

References

EPSS Score

10% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.