CVE-2011-0959
Cisco Unified Operations Manager < 8.6 - Cross-Site Scripting via Multiple Parameters
Title source: llmExploitation Summary
EIP tracks 6 public exploits for CVE-2011-0959. PoCs published by Sense of Security.
AI-analyzed exploit summary The provided text describes a cross-site scripting (XSS) vulnerability in Cisco Unified Operations Manager. It includes example URLs demonstrating the vulnerability but does not contain executable exploit code.
Description
Multiple cross-site scripting (XSS) vulnerabilities in Cisco Unified Operations Manager (CUOM) before 8.6 allow remote attackers to inject arbitrary web script or HTML via (1) the extn parameter to iptm/advancedfind.do, (2) the deviceInstanceName parameter to iptm/ddv.do, the (3) cmd or (4) group parameter to iptm/eventmon, the (5) clusterName or (6) deviceName parameter to iptm/faultmon/ui/dojo/Main/eventmon_wrapper.jsp, or the (7) ccmName or (8) clusterName parameter to iptm/logicalTopo.do, aka Bug ID CSCtn61716.
Exploits (6)
The provided text describes a cross-site scripting (XSS) vulnerability in Cisco Unified Operations Manager. It includes example URLs demonstrating the vulnerability but does not contain executable exploit code.
This exploit demonstrates multiple XSS vulnerabilities in Cisco Unified Operations Manager by injecting arbitrary JavaScript code via unsanitized input parameters. The PoC includes example URLs that trigger alerts when accessed.
The provided text describes a cross-site scripting (XSS) vulnerability in Cisco Unified Operations Manager. It includes a proof-of-concept URL demonstrating the vulnerability but does not contain executable exploit code.
This exploit demonstrates a reflected XSS vulnerability in Cisco Unified Operations Manager by injecting arbitrary JavaScript via unsanitized input parameters in the URL. The PoC uses the `alert(1)` payload to confirm execution in the context of the affected site.
The exploit demonstrates XSS vulnerabilities in Cisco Unified Operations Manager by injecting arbitrary JavaScript via unsanitized input parameters in the URL. The PoC includes crafted URLs that trigger alert pop-ups, confirming the vulnerability.
This advisory details multiple vulnerabilities in Cisco Unified Operations Manager, including blind SQL injection, reflected XSS, and directory traversal. It provides specific exploit paths and technical details for each CVE.