First published: Fri May 20 2011(Updated: )
Cross-site scripting (XSS) vulnerability in cwhp/device.center.do in the Help servlet in Cisco CiscoWorks Common Services 3.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the device parameter, aka Bug ID CSCto12704.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco CiscoWorks Common Services | =2.2 | |
Cisco CiscoWorks Common Services | <=3.3 | |
Cisco CiscoWorks Common Services | =3.0.6 | |
Cisco CiscoWorks Common Services | =3.0.4 | |
Cisco CiscoWorks Common Services | =3.2 | |
Cisco CiscoWorks Common Services | =1.0 | |
Cisco CiscoWorks Common Services | =3.1.1 | |
Cisco CiscoWorks Common Services | =3.0 | |
Cisco CiscoWorks Common Services | =3.1 | |
Cisco CiscoWorks Common Services | =3.0.3 | |
Cisco CiscoWorks Common Services | =3.0.5 | |
<=3.3 | ||
=1.0 | ||
=2.2 | ||
=3.0 | ||
=3.0.3 | ||
=3.0.4 | ||
=3.0.5 | ||
=3.0.6 | ||
=3.1 | ||
=3.1.1 | ||
=3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-0961 is classified as a moderate severity vulnerability due to its potential for exploitation through cross-site scripting.
To address CVE-2011-0961, upgrade to a patched version of CiscoWorks Common Services beyond version 3.3.
CVE-2011-0961 impacts CiscoWorks Common Services versions 1.0 through 3.3.
CVE-2011-0961 is associated with cross-site scripting (XSS) attacks, allowing attackers to inject scripts into web pages.
Any user of the affected versions of CiscoWorks Common Services may be at risk of exploitation due to CVE-2011-0961.