Описание
Multiple cross-site scripting (XSS) vulnerabilities in the HTTP server in Cisco IOS 12.4(23) allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the default URI under (1) level/15/exec/-/ or (2) exec/, a different vulnerability than CVE-2008-3821.
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:o:cisco:ios:12.4\(23\):*:*:*:*:*:*:*
EPSS
Процентиль: 90%
0.05418
Низкий
4.3 Medium
CVSS2
Дефекты
CWE-79
Связанные уязвимости
github
почти 4 года назад
Multiple cross-site scripting (XSS) vulnerabilities in the HTTP server in Cisco IOS 12.4(23) allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the default URI under (1) level/15/exec/-/ or (2) exec/, a different vulnerability than CVE-2008-3821.
EPSS
Процентиль: 90%
0.05418
Низкий
4.3 Medium
CVSS2
Дефекты
CWE-79