CVE-2011-0962
Cisco Unified Operations Manager < 8.5 - XSS
Title source: ruleDescription
Cross-site scripting (XSS) vulnerability in CSCOnm/servlet/com.cisco.nm.help.ServerHelpEngine in the Common Services Device Center in Cisco Unified Operations Manager (CUOM) before 8.6 allows remote attackers to inject arbitrary web script or HTML via the tag parameter, aka Bug ID CSCto12712.
Exploits (2)
exploitdb
WRITEUP
VERIFIED
by Sense of Security · textremotewindows
https://www.exploit-db.com/exploits/17304
exploitdb
WRITEUP
VERIFIED
by Sense of Security · textremotehardware
https://www.exploit-db.com/exploits/35780
References (5)
Scores
EPSS
0.0551
EPSS Percentile
90.1%
Classification
CWE
CWE-79
Status
published
Affected Products (11)
cisco/unified_operations_manager
< 8.5
cisco/unified_operations_manager
cisco/unified_operations_manager
cisco/unified_operations_manager
cisco/unified_operations_manager
cisco/unified_operations_manager
cisco/unified_operations_manager
cisco/unified_operations_manager
cisco/unified_operations_manager
cisco/unified_operations_manager
n/a/n/a
Timeline
Published
May 20, 2011
Tracked Since
Feb 18, 2026