ID
VAR-E-201105-0015
CVE
cve_id: | CVE-2011-0962 | Trust: 2.4 |
cve_id: | CVE-2011-0959 | Trust: 0.5 |
cve_id: | CVE-2011-0960 | Trust: 0.5 |
cve_id: | CVE-2011-0961 | Trust: 0.5 |
cve_id: | CVE-2011-0966 | Trust: 0.5 |
EDB ID
35780
TITLE
Cisco Unified Operations Manager 8.5 - Common Services Device Center Cross-Site Scripting - Hardware remote Exploit
Trust: 0.6
DESCRIPTION
Cisco Unified Operations Manager 8.5 - Common Services Device Center Cross-Site Scripting. CVE-2011-0962CVE-72421 . remote exploit for Hardware platform
Trust: 0.6
AFFECTED PRODUCTS
vendor: | cisco | model: | unified operations manager | scope: | eq | version: | 8.5 | Trust: 1.3 |
vendor: | cisco | model: | unified operations manager | scope: | - | version: | - | Trust: 0.5 |
vendor: | cisco | model: | unified operations manager | scope: | eq | version: | 2.0.3 | Trust: 0.3 |
vendor: | cisco | model: | unified operations manager | scope: | eq | version: | 2.0.2 | Trust: 0.3 |
vendor: | cisco | model: | unified operations manager | scope: | eq | version: | 2.0.1 | Trust: 0.3 |
vendor: | cisco | model: | unified operations manager | scope: | eq | version: | 8.0 | Trust: 0.3 |
vendor: | cisco | model: | unified operations manager | scope: | eq | version: | 2.3 | Trust: 0.3 |
vendor: | cisco | model: | unified operations manager | scope: | eq | version: | 2.2 | Trust: 0.3 |
vendor: | cisco | model: | unified operations manager sp1 | scope: | eq | version: | 2.1 | Trust: 0.3 |
vendor: | cisco | model: | unified operations manager | scope: | eq | version: | 2.1 | Trust: 0.3 |
vendor: | cisco | model: | unified operations manager | scope: | ne | version: | 8.6 | Trust: 0.3 |
EXPLOIT
source: https://www.securityfocus.com/bid/47903/info
Cisco Unified Operations Manager is prone to a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied data.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
This issue is being tracked by Cisco Bug ID CSCto12712.
Cisco Unified Operations Manager versions prior to 8.6 are vulnerable.
http://www.example.com/CSCOnm/servlet/com.cisco.nm.help.ServerHelpEngine?tag=Portal_introductionhomepage61a8b"%3balert(1)
Trust: 1.0
EXPLOIT LANGUAGE
txt
Trust: 0.6
PRICE
free
Trust: 0.6
TYPE
Common Services Device Center Cross-Site Scripting
Trust: 1.0
TAGS
tag: | exploit | Trust: 0.5 |
tag: | remote | Trust: 0.5 |
tag: | vulnerability | Trust: 0.5 |
tag: | xss | Trust: 0.5 |
tag: | sql injection | Trust: 0.5 |
CREDITS
Sense of Security
Trust: 0.6
EXTERNAL IDS
db: | NVD | id: | CVE-2011-0962 | Trust: 2.4 |
db: | EXPLOIT-DB | id: | 35780 | Trust: 1.9 |
db: | BID | id: | 47903 | Trust: 1.9 |
db: | EDBNET | id: | 57179 | Trust: 0.6 |
db: | NVD | id: | CVE-2011-0961 | Trust: 0.5 |
db: | NVD | id: | CVE-2011-0959 | Trust: 0.5 |
db: | NVD | id: | CVE-2011-0960 | Trust: 0.5 |
db: | NVD | id: | CVE-2011-0966 | Trust: 0.5 |
db: | PACKETSTORM | id: | 101518 | Trust: 0.5 |
REFERENCES
url: | https://nvd.nist.gov/vuln/detail/cve-2011-0962 | Trust: 2.1 |
url: | https://www.securityfocus.com/bid/47903/info | Trust: 1.0 |
url: | https://www.exploit-db.com/exploits/35780/ | Trust: 0.6 |
url: | https://nvd.nist.gov/vuln/detail/cve-2011-0960 | Trust: 0.5 |
url: | https://nvd.nist.gov/vuln/detail/cve-2011-0959 | Trust: 0.5 |
url: | https://nvd.nist.gov/vuln/detail/cve-2011-0961 | Trust: 0.5 |
url: | https://nvd.nist.gov/vuln/detail/cve-2011-0966 | Trust: 0.5 |
url: | https://www.exploit-db.com/exploits/35780 | Trust: 0.3 |
url: | http://www.cisco.com/en/us/products/ps6535/index.html | Trust: 0.3 |
url: | http://www.senseofsecurity.com.au/advisories/sos-11-006.pdf | Trust: 0.3 |
url: | http://tools.cisco.com/security/center/viewalert.x?alertid=23087 | Trust: 0.3 |
SOURCES
db: | BID | id: | 47903 |
db: | PACKETSTORM | id: | 101518 |
db: | EXPLOIT-DB | id: | 35780 |
db: | EDBNET | id: | 57179 |
LAST UPDATE DATE
2022-07-27T09:19:18.060000+00:00
SOURCES UPDATE DATE
db: | BID | id: | 47903 | date: | 2011-05-18T00:00:00 |
SOURCES RELEASE DATE
db: | BID | id: | 47903 | date: | 2011-05-18T00:00:00 |
db: | PACKETSTORM | id: | 101518 | date: | 2011-05-18T14:17:13 |
db: | EXPLOIT-DB | id: | 35780 | date: | 2011-05-18T00:00:00 |
db: | EDBNET | id: | 57179 | date: | 2011-05-18T00:00:00 |