Home arrow Vendor Advisories arrow Cisco arrow IOS HTTP Server Command Injection Vulnerability
Friday, 10 February 2012
 
spacer.png, 0 kB
spacer.png, 0 kB
spacer.png, 0 kB
IOS HTTP Server Command Injection Vulnerability
Friday, 02 December 2005
A vulnerability exists in the IOS HTTP server in which HTML code inserted into dynamically generated output, such as the output from a show buffers command, will be passed to the browser requesting the page. This HTML code could be interpreted by the client browser and potentially execute malicious commands against the device or other possible cross-site scripting attacks. Successful exploitation of this vulnerability requires that a user browse a page containing dynamic content in which HTML commands have been injected.
 
spacer.png, 0 kB
     

© 2012 Intellect Information Technology Pty Ltd, Melbourne, Australia.

This page was loaded in 0.070 seconds.