CVE-2020-3466
published 2020-08-26CVE-2020-3466: Multiple vulnerabilities in the web-based management interface of Cisco DNA Center software could allow an unauthenticated, remote attacker to conduct a…
PriorityP428medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
0.92%
56.3th percentile
Multiple vulnerabilities in the web-based management interface of Cisco DNA Center software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. The vulnerabilities exist because the web-based management interface on an affected device does not properly validate user-supplied input. An attacker could exploit these vulnerabilities by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_digital_network_architecture_center | — | — |
| cisco | dna_center | — | — |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv3.04.7MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_cisco4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco DNA Center Cross-Site Scripting Vulnerabilities
vendor_cisco·2020-08-19·CVSS 4.7
CVE-2020-3466 [MEDIUM] CWE-79 Cisco DNA Center Cross-Site Scripting Vulnerabilities
Cisco DNA Center Cross-Site Scripting Vulnerabilities
Multiple vulnerabilities in the web-based management interface of Cisco DNA Center software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device.
The vulnerabilities exist because the web-based management interface on an affected device does not properly validate user-supplied input. An attacker could exploit these vulnerabilities by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.
There are no workarounds that address these vulnerabilities.
This advisory is availa
Cisco
Cisco DNA Center Cross-Site Scripting Vulnerabilities
vendor_cisco·CVSS 3.0
CVE-2020-3466 Cisco DNA Center Cross-Site Scripting Vulnerabilities
CVE-2020-3466: Cisco DNA Center Cross-Site Scripting Vulnerabilities
Multiple vulnerabilities in the web-based management interface of Cisco DNA Center software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. The vulnerabilities exist because the web-based management interface on an affected device does not properly validate user-supplied input. An attacker could exploit these vulnerabilities by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. There are no
CVSS: 3.0
CWE: CWE-79, CWE-79
Bug IDs: CSCvr72551, CSCvr74
GHSA
GHSA-72j8-j6qp-6pfv: Multiple vulnerabilities in the web-based management interface of Cisco DNA Center software could allow an unauthenticated, remote attacker to conduct
ghsa_unreviewed·2022-05-24
CVE-2020-3466 [MEDIUM] CWE-79 GHSA-72j8-j6qp-6pfv: Multiple vulnerabilities in the web-based management interface of Cisco DNA Center software could allow an unauthenticated, remote attacker to conduct
Multiple vulnerabilities in the web-based management interface of Cisco DNA Center software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. The vulnerabilities exist because the web-based management interface on an affected device does not properly validate user-supplied input. An attacker could exploit these vulnerabilities by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.
Suricata
ET WEB_SPECIFIC_APPS BP Blog SQL Injection Attempt -- default.asp layout ASCII
suricata·2010-07-30·CVSS 7.5
CVE-2007-1445 [HIGH] ET WEB_SPECIFIC_APPS BP Blog SQL Injection Attempt -- default.asp layout ASCII
ET WEB_SPECIFIC_APPS BP Blog SQL Injection Attempt -- default.asp layout ASCII
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS BP Blog SQL Injection Attempt -- default.asp layout ASCII"; flow:established,to_server; http.uri; content:"/default.asp?"; nocase; content:"layout="; nocase; content:"ASCII("; nocase; content:"SELECT"; nocase; distance:0; reference:cve,CVE-2007-1445; reference:url,www.milw0rm.com/exploits/3466; classtype:web-application-attack; sid:2004335; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_10, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id
Suricata
ET WEB_SPECIFIC_APPS BP Blog SQL Injection Attempt -- default.asp layout DELETE
suricata·2010-07-30·CVSS 7.5
CVE-2007-1445 [HIGH] ET WEB_SPECIFIC_APPS BP Blog SQL Injection Attempt -- default.asp layout DELETE
ET WEB_SPECIFIC_APPS BP Blog SQL Injection Attempt -- default.asp layout DELETE
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS BP Blog SQL Injection Attempt -- default.asp layout DELETE"; flow:established,to_server; http.uri; content:"/default.asp?"; nocase; content:"layout="; nocase; content:"DELETE"; nocase; content:"FROM"; nocase; distance:0; reference:cve,CVE-2007-1445; reference:url,www.milw0rm.com/exploits/3466; classtype:web-application-attack; sid:2004334; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_10, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id
Suricata
ET WEB_SPECIFIC_APPS BP Blog SQL Injection Attempt -- default.asp layout SELECT
suricata·2010-07-30·CVSS 7.5
CVE-2007-1445 [HIGH] ET WEB_SPECIFIC_APPS BP Blog SQL Injection Attempt -- default.asp layout SELECT
ET WEB_SPECIFIC_APPS BP Blog SQL Injection Attempt -- default.asp layout SELECT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS BP Blog SQL Injection Attempt -- default.asp layout SELECT"; flow:established,to_server; http.uri; content:"/default.asp?"; nocase; content:"layout="; nocase; content:"SELECT"; nocase; content:"FROM"; nocase; distance:0; reference:cve,CVE-2007-1445; reference:url,www.milw0rm.com/exploits/3466; classtype:web-application-attack; sid:2004331; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_10, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id
Suricata
ET WEB_SPECIFIC_APPS BP Blog SQL Injection Attempt -- default.asp layout UNION SELECT
suricata·2010-07-30·CVSS 7.5
CVE-2007-1445 [HIGH] ET WEB_SPECIFIC_APPS BP Blog SQL Injection Attempt -- default.asp layout UNION SELECT
ET WEB_SPECIFIC_APPS BP Blog SQL Injection Attempt -- default.asp layout UNION SELECT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS BP Blog SQL Injection Attempt -- default.asp layout UNION SELECT"; flow:established,to_server; http.uri; content:"/default.asp?"; nocase; content:"layout="; nocase; content:"UNION"; nocase; content:"SELECT"; nocase; distance:0; reference:cve,CVE-2007-1445; reference:url,www.milw0rm.com/exploits/3466; classtype:web-application-attack; sid:2004332; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_10, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_
Suricata
ET WEB_SPECIFIC_APPS BP Blog SQL Injection Attempt -- default.asp layout UPDATE
suricata·2010-07-30·CVSS 7.5
CVE-2007-1445 [HIGH] ET WEB_SPECIFIC_APPS BP Blog SQL Injection Attempt -- default.asp layout UPDATE
ET WEB_SPECIFIC_APPS BP Blog SQL Injection Attempt -- default.asp layout UPDATE
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS BP Blog SQL Injection Attempt -- default.asp layout UPDATE"; flow:established,to_server; http.uri; content:"/default.asp?"; nocase; content:"layout="; nocase; content:"UPDATE"; nocase; content:"SET"; nocase; distance:0; reference:cve,CVE-2007-1445; reference:url,www.milw0rm.com/exploits/3466; classtype:web-application-attack; sid:2004336; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_10, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T
Suricata
ET WEB_SPECIFIC_APPS BP Blog SQL Injection Attempt -- default.asp layout INSERT
suricata·2010-07-30·CVSS 7.5
CVE-2007-1445 [HIGH] ET WEB_SPECIFIC_APPS BP Blog SQL Injection Attempt -- default.asp layout INSERT
ET WEB_SPECIFIC_APPS BP Blog SQL Injection Attempt -- default.asp layout INSERT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS BP Blog SQL Injection Attempt -- default.asp layout INSERT"; flow:established,to_server; http.uri; content:"/default.asp?"; nocase; content:"layout="; nocase; content:"INSERT"; nocase; content:"INTO"; nocase; distance:0; reference:cve,CVE-2007-1445; reference:url,www.milw0rm.com/exploits/3466; classtype:web-application-attack; sid:2004333; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_10, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id
No public exploits indexed.
No writeups or analysis indexed.
2020-08-26
Published