Cross-Site Scripting Vulnerability in CiscoWorks Common Services
CVE-2011-0961

Currently unrated

Key Information:

Vendor
Cisco
Vendor
CVE Published:
20 May 2011

Summary

A cross-site scripting vulnerability exists in the Help servlet of CiscoWorks Common Services, specifically at the cwhp/device.center.do endpoint. This flaw allows remote attackers to inject arbitrary web scripts or HTML through the 'device' parameter. Exploitation of this vulnerability could enable attackers to execute malicious scripts in the context of users' browsers, leading to potential data theft, session hijacking, or other malicious actions.

References

EPSS Score

21% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.