← All CVEs

CVE-2011-0959

medium · 4.3

Multiple cross-site scripting (XSS) vulnerabilities in Cisco Unified Operations Manager (CUOM) before 8.6 allow remote attackers to inject arbitrary web script or HTML via (1) the extn parameter to iptm/advancedfind.do, (2) the deviceInstanceName parameter to iptm/ddv.do, the (3) cmd or (4) group parameter to iptm/eventmon, the (5) clusterName or (6) deviceName parameter to iptm/faultmon/ui/dojo/Main/eventmon_wrapper.jsp, or the (7) ccmName or (8) clusterName parameter to iptm/logicalTopo.do, aka Bug ID CSCtn61716.

4.3
CVSS
21.5%
EPSS (exploit prob.)
98th
EPSS percentile
2011-05-20
Published

AV:N/AC:M/Au:N/C:N/I:P/A:N

Weaknesses

CWE-79

Affected products

VendorProductAffected versions
ciscounified_operations_manager<= 8.5
ciscounified_operations_manager1.1
ciscounified_operations_manager2.0
ciscounified_operations_manager2.0.1
ciscounified_operations_manager2.0.2
ciscounified_operations_manager2.0.3
ciscounified_operations_manager2.1
ciscounified_operations_manager2.2
ciscounified_operations_manager2.3
ciscounified_operations_manager8.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2011-0959