2.6

CVE-2005-3921

Exploit

Cross-site scripting (XSS) vulnerability in Cisco IOS Web Server for IOS 12.0(2a) allows remote attackers to inject arbitrary web script or HTML by (1) packets containing HTML that an administrator views via an HTTP interface to the contents of memory buffers, as demonstrated by the URI /level/15/exec/-/buffers/assigned/dump; or (2) sending the router Cisco Discovery Protocol (CDP) packets with HTML payload that an administrator views via the CDP status pages.  NOTE: these vectors were originally reported as being associated with the dump and packet options in /level/15/exec/-/show/buffers.

Data is provided by the National Vulnerability Database (NVD)
CiscoIos Version <= 12.3
CiscoIos Version12.3b
CiscoIos Version12.3bc
CiscoIos Version12.3bw
CiscoIos Version12.3ja
CiscoIos Version12.3jk
CiscoIos Version12.3jx
CiscoIos Version12.3t
CiscoIos Version12.3tpc
CiscoIos Version12.3xa
CiscoIos Version12.3xb
CiscoIos Version12.3xc
CiscoIos Version12.3xd
CiscoIos Version12.3xe
CiscoIos Version12.3xf
CiscoIos Version12.3xg
CiscoIos Version12.3xh
CiscoIos Version12.3xi
CiscoIos Version12.3xj
CiscoIos Version12.3xk
CiscoIos Version12.3xl
CiscoIos Version12.3xm
CiscoIos Version12.3xn
CiscoIos Version12.3xq
CiscoIos Version12.3xr
CiscoIos Version12.3xs
CiscoIos Version12.3xt
CiscoIos Version12.3xu
CiscoIos Version12.3xv
CiscoIos Version12.3xw
CiscoIos Version12.3xx
CiscoIos Version12.3xy
CiscoIos Version12.3xz
CiscoIos Version12.3ya
CiscoIos Version12.3yb
CiscoIos Version12.3yc
CiscoIos Version12.3yd
CiscoIos Version12.3ye
CiscoIos Version12.3yf
CiscoIos Version12.3yg
CiscoIos Version12.3yh
CiscoIos Version12.3yi
CiscoIos Version12.3yj
CiscoIos Version12.3yk
CiscoIos Version12.3yl
CiscoIos Version12.3ym
CiscoIos Version12.3yn
CiscoIos Version12.3yq
CiscoIos Version12.3yr
CiscoIos Version12.3ys
CiscoIos Version12.3yt
CiscoIos Version12.3yu
CiscoIos Version12.3yw
CiscoIos Version12.3yx
CiscoIos Version12.4
CiscoIos Version12.4mr
CiscoIos Version12.4t
CiscoIos Version12.4xa
CiscoIos Version12.4xb
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.6% 0.809
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 2.6 4.9 2.9
AV:N/AC:H/Au:N/C:N/I:P/A:N