CVE-2011-0961
CiscoWorks Common Services < 3.3 - Cross-Site Scripting via Device Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2011-0961. PoCs published by Sense of Security.
AI-analyzed exploit summary This advisory details multiple vulnerabilities in Cisco Unified Operations Manager, including blind SQL injection, reflected XSS, and directory traversal. It provides specific exploit paths and technical details for each CVE.
Description
Cross-site scripting (XSS) vulnerability in cwhp/device.center.do in the Help servlet in Cisco CiscoWorks Common Services 3.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the device parameter, aka Bug ID CSCto12704.
Exploits (2)
This advisory details multiple vulnerabilities in Cisco Unified Operations Manager, including blind SQL injection, reflected XSS, and directory traversal. It provides specific exploit paths and technical details for each CVE.
This exploit demonstrates a cross-site scripting (XSS) vulnerability in CiscoWorks Common Services by injecting a script tag into the 'device' parameter of a URL. The vulnerability arises due to insufficient input sanitization, allowing arbitrary JavaScript execution in the context of the affected website.