CVE-2005-3921

Cisco IOS - Cross-Site Scripting via HTTP Interface or CDP Status Pages

Title source: llm
STIX 2.1

Description

Cross-site scripting (XSS) vulnerability in Cisco IOS Web Server for IOS 12.0(2a) allows remote attackers to inject arbitrary web script or HTML by (1) packets containing HTML that an administrator views via an HTTP interface to the contents of memory buffers, as demonstrated by the URI /level/15/exec/-/buffers/assigned/dump; or (2) sending the router Cisco Discovery Protocol (CDP) packets with HTML payload that an administrator views via the CDP status pages. NOTE: these vectors were originally reported as being associated with the dump and packet options in /level/15/exec/-/show/buffers.

References (12)

Core 12
Core References
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/17780
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2005/2657
Vendor Advisory vendor-advisory x_refsource_cisco
http://www.cisco.com/warp/public/707/cisco-sa-20051201-http.shtml
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/18528
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5867
Various Sources third-party-advisory x_refsource_idefense
http://www.idefense.com/intelligence/vulnerabilities/display.php?id=372
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/417916/100/0/threaded
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/227
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/15602
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1015275
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/16291

Scores

EPSS 0.0276
EPSS Percentile 84.7%

Details

Status published
Products (50)
cisco/ios 12.3\(1a\)
cisco/ios 12.3\(2\)ja
cisco/ios 12.3\(2\)ja5
cisco/ios 12.3\(2\)jk
cisco/ios 12.3\(2\)jk1
cisco/ios 12.3\(2\)t3
cisco/ios 12.3\(2\)t8
cisco/ios 12.3\(2\)xa4
cisco/ios 12.3\(2\)xa5
cisco/ios 12.3\(2\)xc1
... and 40 more
Published Nov 30, 2005
Tracked Since Feb 18, 2026