Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2011-0962

Severity
4.3MEDIUM
EPSS
5.5%
top 9.77%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedMay 20
Latest updateMay 17

Description

Cross-site scripting (XSS) vulnerability in CSCOnm/servlet/com.cisco.nm.help.ServerHelpEngine in the Common Services Device Center in Cisco Unified Operations Manager (CUOM) before 8.6 allows remote attackers to inject arbitrary web script or HTML via the tag parameter, aka Bug ID CSCto12712.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-hq75-7jp8-q8x3: Cross-site scripting (XSS) vulnerability in CSCOnm/servlet/com2022-05-17
CVEList
CVE-2011-0962: Cross-site scripting (XSS) vulnerability in CSCOnm/servlet/com2011-05-20

💥Exploits & PoCs

2
Exploit-DB
Cisco Unified Operations Manager 8.5 - Common Services Device Center Cross-Site Scripting2011-05-18
Exploit-DB
Cisco Unified Operations Manager - Multiple Vulnerabilities2011-05-18

🔍Detection Rules

1
Suricata
ET WEB_SPECIFIC_APPS Cisco Common Services Framework Reflective XSS Attempt2011-05-18

📋Vendor Advisories

1
Cisco
Cisco Unified Operations Manager Common Services Device Center Cross-Site Scripting Vulnerability2011-05-18