[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

253928

 
 

909

 
 

198006

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2005-3921Date: (C)2005-11-30   (M)2023-12-22


Cross-site scripting (XSS) vulnerability in Cisco IOS Web Server for IOS 12.0(2a) allows remote attackers to inject arbitrary web script or HTML by (1) packets containing HTML that an administrator views via an HTTP interface to the contents of memory buffers, as demonstrated by the URI /level/15/exec/-/buffers/assigned/dump; or (2) sending the router Cisco Discovery Protocol (CDP) packets with HTML payload that an administrator views via the CDP status pages. NOTE: these vectors were originally reported as being associated with the dump and packet options in /level/15/exec/-/show/buffers.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 2.6
Exploit Score: 4.9
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: HIGH
Authentication: NONE
Confidentiality: NONE
Integrity: PARTIAL
Availability: NONE
  
Reference:
SECTRACK-1015275
BID-15602
BID-16291
SECUNIA-17780
SECUNIA-18528
http://www.securityfocus.com/archive/1/417916/100/0/threaded
http://www.cisco.com/warp/public/707/cisco-sa-20051201-http.shtml
http://www.idefense.com/intelligence/vulnerabilities/display.php?id=372
SREASON-227
ADV-2005-2657
http://www.infohacking.com/INFOHACKING_RESEARCH/Our_Advisories/cisco/index.html
oval:org.mitre.oval:def:5867

CPE    58
cpe:/o:cisco:ios:12.3jx
cpe:/o:cisco:ios:12.3ja
cpe:/o:cisco:ios:12.3jk
cpe:/o:cisco:ios:12.4t
...

© SecPod Technologies