Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A vulnerability in the web framework code of Cisco Prime Service Catalog could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the user of the web interface of the affected system. More Information: CSCvc79842 CSCvc79846 CSCvc79855 CSCvc79873 CSCvc79882 CSCvc79891. Known Affected Releases: 11.1.2.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Cisco Prime Service Catalog 跨站脚本漏洞
Vulnerability Description
Cisco Prime Service Catalog(PSC)是美国思科公司(Cisco)的一套通过单一的门户网站提供所有IT服务的服务目录解决方案。该方案支持自动化订购计算、网络、存储和其他数据中心资源的统一服务目录。 Cisco PSC中的Web框架代码存在跨站脚本漏洞,该漏洞源于程序没有充分的验证传递到Web服务器上的参数。远程攻击者可通过诱使用户访问恶意的链接或拦截用户请求并注入恶意代码利用该漏洞在受影响的站点上下文中执行任意代码或获取基于浏览器的敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A