VulnerabilityModified
CVE-2008-3821
Multiple cross-site scripting (XSS) vulnerabilities in the HTTP server in Cisco IOS 11.0 through 12.4 allow remote attackers to inject arbitrary web script or HTML via (1) the query string to the ping program or (2) unspecified other aspects of the URI.
MEDIUM 4.3EPSS 5.45%
Does this matter?
Lower severity and a low EPSS score (5.45%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple cross-site scripting (XSS) vulnerabilities in the HTTP server in Cisco IOS 11.0 through 12.4 allow remote attackers to inject arbitrary web script or HTML via (1) the query string to the ping program or (2) unspecified other aspects of the URI.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 5.45% probability · 92th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- cisco/ios
- Source
- psirt@cisco.com
References
- http://jvn.jp/en/jp/JVN28344798/index.htmlThird Party Advisory, VDB Entry
- http://osvdb.org/51393Broken Link
- http://osvdb.org/51394Broken Link
- http://secunia.com/advisories/33461Third Party Advisory
- http://securityreason.com/securityalert/4916Third Party Advisory
- http://securitytracker.com/id?1021598Third Party Advisory, VDB Entry
- http://www.cisco.com/en/US/products/products_security_response09186a0080a5c501.htmlVendor Advisory
- http://www.procheckup.com/vulnerability_manager/vulnerabilities/pr08-19Exploit
- http://www.securityfocus.com/archive/1/500063/100/0/threaded
- http://www.securityfocus.com/bid/33260Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2009/0138Not Applicable
- https://exchange.xforce.ibmcloud.com/vulnerabilities/47947Third Party Advisory, VDB Entry
- http://jvn.jp/en/jp/JVN28344798/index.htmlThird Party Advisory, VDB Entry
- http://osvdb.org/51393Broken Link
- http://osvdb.org/51394Broken Link
- http://secunia.com/advisories/33461Third Party Advisory
- http://securityreason.com/securityalert/4916Third Party Advisory
- http://securitytracker.com/id?1021598Third Party Advisory, VDB Entry
- http://www.cisco.com/en/US/products/products_security_response09186a0080a5c501.htmlVendor Advisory
- http://www.procheckup.com/vulnerability_manager/vulnerabilities/pr08-19Exploit
- http://www.securityfocus.com/archive/1/500063/100/0/threaded
- http://www.securityfocus.com/bid/33260Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2009/0138Not Applicable
- https://exchange.xforce.ibmcloud.com/vulnerabilities/47947Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.