CVE-2008-3821
Cisco IOS <12.4 - XSS
Title source: llmDescription
Multiple cross-site scripting (XSS) vulnerabilities in the HTTP server in Cisco IOS 11.0 through 12.4 allow remote attackers to inject arbitrary web script or HTML via (1) the query string to the ping program or (2) unspecified other aspects of the URI.
Exploits (1)
exploitdb
WRITEUP
VERIFIED
by Adrian Pastor · textremotehardware
https://www.exploit-db.com/exploits/32723
References (12)
Scores
EPSS
0.0893
EPSS Percentile
92.5%
Classification
CWE
CWE-79
Status
published
Affected Products (50)
cisco/ios
cisco/ios
cisco/ios
cisco/ios
cisco/ios
cisco/ios
cisco/ios
cisco/ios
cisco/ios
cisco/ios
cisco/ios
cisco/ios
cisco/ios
cisco/ios
cisco/ios
... and 35 more
Timeline
Published
Jan 16, 2009
Tracked Since
Feb 18, 2026