CVE-2005-3921
published 2005-11-30CVE-2005-3921: Cross-site scripting (XSS) vulnerability in Cisco IOS Web Server for IOS 12.0(2a) allows remote attackers to inject arbitrary web script or HTML by (1) packets…
PriorityP416low2.6CVSS 2.0
AVNACHAuNCNIPAN
EPSS
2.76%
84.8th percentile
Cross-site scripting (XSS) vulnerability in Cisco IOS Web Server for IOS 12.0(2a) allows remote attackers to inject arbitrary web script or HTML by (1) packets containing HTML that an administrator views via an HTTP interface to the contents of memory buffers, as demonstrated by the URI /level/15/exec/-/buffers/assigned/dump; or (2) sending the router Cisco Discovery Protocol (CDP) packets with HTML payload that an administrator views via the CDP status pages. NOTE: these vectors were originally reported as being associated with the dump and packet options in /level/15/exec/-/show/buffers.
Affected
225 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | <= 12.3 | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
CVSS provenance
nvdv2.02.6LOWAV:N/AC:H/Au:N/C:N/I:P/A:N
vendor_cisco7.6HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
IOS HTTP Server Command Injection Vulnerability
vendor_cisco·2005-12-01·CVSS 7.6
CVE-2005-3921 [HIGH] CWE-79 IOS HTTP Server Command Injection Vulnerability
IOS HTTP Server Command Injection Vulnerability
A vulnerability exists in the IOS HTTP server in which HTML code
inserted into dynamically generated output, such as the output from a
show buffers command, will be passed to the browser
requesting the page. This HTML code could be interpreted by the client browser
and potentially execute malicious commands against the device or other possible
cross-site scripting attacks. Successful exploitation of this vulnerability
requires that a user browse a page containing dynamic content in which HTML
commands have been injected.
Cisco will be making free software available to address this
vulnerability for affected customers. There are workarounds available to
mitigate the effects of the vulnerability.
This advisory is posted at
https://sec.cloudapp
Cisco
IOS HTTP Server Command Injection Vulnerability
vendor_cisco
CVE-2005-3921 IOS HTTP Server Command Injection Vulnerability
CVE-2005-3921: IOS HTTP Server Command Injection Vulnerability
A vulnerability exists in the IOS HTTP server in which HTML code inserted into dynamically generated output, such as the output from a show buffers command, will be passed to the browser requesting the page. This HTML code could be interpreted by the client browser and potentially execute malicious commands against the device or other possible cross-site scripting attacks. Successful exploitation of this vulnerability requires that a user browse a page containing dynamic content in which HTML commands have been injected. Cisco will be making free software available to address this vulnerability for affected customers. There are
CWE: CWE-79, CWE-79
Bug IDs: CSCsc64976, CSCsc64976
GHSA
GHSA-rr7q-672p-8qm6: Cross-site scripting (XSS) vulnerability in Cisco IOS Web Server for IOS 12
ghsa_unreviewed·2022-05-01
CVE-2005-3921 [LOW] GHSA-rr7q-672p-8qm6: Cross-site scripting (XSS) vulnerability in Cisco IOS Web Server for IOS 12
Cross-site scripting (XSS) vulnerability in Cisco IOS Web Server for IOS 12.0(2a) allows remote attackers to inject arbitrary web script or HTML by (1) packets containing HTML that an administrator views via an HTTP interface to the contents of memory buffers, as demonstrated by the URI /level/15/exec/-/buffers/assigned/dump; or (2) sending the router Cisco Discovery Protocol (CDP) packets with HTML payload that an administrator views via the CDP status pages. NOTE: these vectors were originally reported as being associated with the dump and packet options in /level/15/exec/-/show/buffers.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/17780http://secunia.com/advisories/18528http://securityreason.com/securityalert/227http://securitytracker.com/id?1015275http://www.cisco.com/warp/public/707/cisco-sa-20051201-http.shtmlhttp://www.idefense.com/intelligence/vulnerabilities/display.php?id=372http://www.infohacking.com/INFOHACKING_RESEARCH/Our_Advisories/cisco/index.htmlhttp://www.securityfocus.com/archive/1/417916/100/0/threadedhttp://www.securityfocus.com/bid/15602http://www.securityfocus.com/bid/16291http://www.vupen.com/english/advisories/2005/2657https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5867http://secunia.com/advisories/17780http://secunia.com/advisories/18528http://securityreason.com/securityalert/227http://securitytracker.com/id?1015275http://www.cisco.com/warp/public/707/cisco-sa-20051201-http.shtmlhttp://www.idefense.com/intelligence/vulnerabilities/display.php?id=372http://www.infohacking.com/INFOHACKING_RESEARCH/Our_Advisories/cisco/index.htmlhttp://www.securityfocus.com/archive/1/417916/100/0/threadedhttp://www.securityfocus.com/bid/15602http://www.securityfocus.com/bid/16291http://www.vupen.com/english/advisories/2005/2657https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5867
2005-11-30
Published