Cisco Prime Service Catalog CVE-2017-3866 Multiple Cross Site Scripting Vulnerabilities
BID:96917
CVE-2017-3866 |Info
Cisco Prime Service Catalog CVE-2017-3866 Multiple Cross Site Scripting Vulnerabilities
Bugtraq ID: | 96917 |
Class: | Input Validation Error |
CVE: |
CVE-2017-3866 |
Remote: | Yes |
Local: | No |
Published: | Mar 15 2017 12:00AM |
Updated: | Mar 15 2017 12:00AM |
Credit: | Cisco |
Vulnerable: |
Cisco Prime Service Catalog 11.1.2 |
Not Vulnerable: |
Cisco Prime Service Catalog 12.0 |
Discussion
Exploit / POC
Cisco Prime Service Catalog CVE-2017-3866 Multiple Cross Site Scripting Vulnerabilities
Attackers can exploit these issues by enticing an unsuspecting victim to follow a malicious URI.
Attackers can exploit these issues by enticing an unsuspecting victim to follow a malicious URI.
Solution / Fix
Cisco Prime Service Catalog CVE-2017-3866 Multiple Cross Site Scripting Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.