Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Cisco IOS HTTP Service HTML Injection Vulnerability

Cisco IOS HTTP service is prone to an HTML-injection vulnerability.

An attacker can submit malicious HTML and script code through the '/level/15/exec/-/buffers/assigned' and '/level/15/exec/-/buffers/all' scripts. This code may run in the browser of an administrator when they attempt to view the contents of memory buffers through the vulnerable scripts of the HTTP service.

IOS 11.0 through 12.4 are affected. IOS XR is not vulnerable.

NOTE: Since this is an HTML-injection vulnerability that targets users of the IOS web interface, devices with the HTTP service disabled are not affected.







 

Privacy Statement
Copyright 2008, SecurityFocus