Multiple cross-site scripting (XSS) vulnerabilities in Cisco Unified Operations Manager (CUOM) before 8.6 allow remote attackers to inject arbitrary web script or HTML via (1) the extn parameter to iptm/advancedfind.do, (2) the deviceInstanceName parameter to iptm/ddv.do, the (3) cmd or (4) group parameter to iptm/eventmon, the (5) clusterName or (6) deviceName parameter to iptm/faultmon/ui/dojo/Main/eventmon_wrapper.jsp, or the (7) ccmName or (8) clusterName parameter to iptm/logicalTopo.do, aka Bug ID CSCtn61716.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published: 2011-05-20T22:00:00

Updated: 2024-08-06T22:14:26.542Z

Reserved: 2011-02-10T00:00:00

Link: CVE-2011-0959

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2011-05-20T22:55:02.907

Modified: 2024-02-14T01:17:43.863

Link: CVE-2011-0959

cve-icon Redhat

No data.