peter bassill · operator
$ cve CVE-2011-0961 JSON

CVE-2011-0961 EXPLOIT

4.3
MEDIUM · CVSS 2.0 · EPSS 5.2% (pctl 92)

Patch early

A public exploit exists.

Description

Cross-site scripting (XSS) vulnerability in cwhp/device.center.do in the Help servlet in Cisco CiscoWorks Common Services 3.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the device parameter, aka Bug ID CSCto12704.

Scoring

CVSS4.3 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS5.15% — more likely to be exploited than 92% of all CVEs
WeaknessCWE-79
On CISA KEVno
Public exploityes
Published2011-05-20
Last modified2026-06-16

Affected (1)

VendorProduct
ciscociscoworks common services

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD