CVE-2005-3921
Last modified
CVE-2005-3921 is a vulnerability of currently unknown severity. Cross-site scripting (XSS) vulnerability in Cisco IOS Web Server for IOS 12.0(2a) allows remote attackers to inject arbitrary web script or HTML by (1) packets containing HTML that an administrator views via an HTTP interface to the contents of memory buffers, as demonstrated by the URI /level/15/exec/-/buffers/assigned/dump; or (2) sending the router Cisco Discovery Protocol (CDP) packets with HTML payload that an administrator views via the CDP status pages. NOTE: these vectors were originally reported as being associated with the dump and packet options in /level/15/exec/-/show/buffers.. EPSS estimates a 2.76% chance of exploitation in the next 30 days.
Description
Cross-site scripting (XSS) vulnerability in Cisco IOS Web Server for IOS 12.0(2a) allows remote attackers to inject arbitrary web script or HTML by (1) packets containing HTML that an administrator views via an HTTP interface to the contents of memory buffers, as demonstrated by the URI /level/15/exec/-/buffers/assigned/dump; or (2) sending the router Cisco Discovery Protocol (CDP) packets with HTML payload that an administrator views via the CDP status pages. NOTE: these vectors were originally reported as being associated with the dump and packet options in /level/15/exec/-/show/buffers.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Ios | <= 12.3 |
| Cisco | Ios | 12.3\(1a\) |
| Cisco | Ios | 12.3\(2\)ja |
| Cisco | Ios | 12.3\(2\)ja5 |
| Cisco | Ios | 12.3\(2\)jk |
| Cisco | Ios | 12.3\(2\)jk1 |
| Cisco | Ios | 12.3\(2\)t3 |
| Cisco | Ios | 12.3\(2\)t8 |
| Cisco | Ios | 12.3\(2\)xa4 |
| Cisco | Ios | 12.3\(2\)xa5 |
| Cisco | Ios | 12.3\(2\)xc1 |
| Cisco | Ios | 12.3\(2\)xc2 |
| Cisco | Ios | 12.3\(2\)xc3 |
| Cisco | Ios | 12.3\(2\)xc4 |
| Cisco | Ios | 12.3\(2\)xe3 |
| Cisco | Ios | 12.3\(2\)xe4 |
| Cisco | Ios | 12.3\(3e\) |
| Cisco | Ios | 12.3\(3h\) |
| Cisco | Ios | 12.3\(3i\) |
| Cisco | Ios | 12.3\(4\)eo1 |
| Cisco | Ios | 12.3\(4\)ja |
| Cisco | Ios | 12.3\(4\)ja1 |
| Cisco | Ios | 12.3\(4\)t |
| Cisco | Ios | 12.3\(4\)t1 |
| Cisco | Ios | 12.3\(4\)t2 |
| Cisco | Ios | 12.3\(4\)t3 |
| Cisco | Ios | 12.3\(4\)t4 |
| Cisco | Ios | 12.3\(4\)t8 |
| Cisco | Ios | 12.3\(4\)tpc11a |
| Cisco | Ios | 12.3\(4\)xd |
| Cisco | Ios | 12.3\(4\)xd1 |
| Cisco | Ios | 12.3\(4\)xd2 |
| Cisco | Ios | 12.3\(4\)xe4 |
| Cisco | Ios | 12.3\(4\)xg1 |
| Cisco | Ios | 12.3\(4\)xg2 |
| Cisco | Ios | 12.3\(4\)xg4 |
| Cisco | Ios | 12.3\(4\)xg5 |
| Cisco | Ios | 12.3\(4\)xh |
| Cisco | Ios | 12.3\(4\)xk |
| Cisco | Ios | 12.3\(4\)xk1 |
| Cisco | Ios | 12.3\(4\)xk3 |
| Cisco | Ios | 12.3\(4\)xk4 |
| Cisco | Ios | 12.3\(4\)xq |
| Cisco | Ios | 12.3\(4\)xq1 |
| Cisco | Ios | 12.3\(5\) |
| Cisco | Ios | 12.3\(5\)b1 |
| Cisco | Ios | 12.3\(5a\) |
| Cisco | Ios | 12.3\(5a\)b |
| Cisco | Ios | 12.3\(5a\)b2 |
| Cisco | Ios | 12.3\(5a\)b5 |
Showing 50 of 225 affected configurations. See NVD for the full list.
References
- http://www.infohacking.com/INFOHACKING_RESEARCH/Our_Advisories/cisco/index.htmlExploit, Vendor Advisory
- http://www.infohacking.com/INFOHACKING_RESEARCH/Our_Advisories/cisco/index.htmlExploit, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2005-3921?
How severe is CVE-2005-3921?
How do I fix CVE-2005-3921?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2005
- CVE-2005-3915The Internet Key Exchange version 1 (IKEv1) implementation i…
- CVE-2005-3916SQL injection vulnerability in memberlist.php in WSN Forum 1…
- CVE-2005-3917SQL injection vulnerability in usersession in CommodityRenta…
- CVE-2005-3918Multiple SQL injection vulnerabilities in OvBB 0.08a allow r…
- CVE-2005-3919Cross-site scripting (XSS) vulnerability in PBLang 4.65 allo…
- CVE-2005-3920SQL injection vulnerability in Babe Logger 2 allows remote a…
- CVE-2005-3922Heap-based buffer overflow in pskcmp.dll in Panda Software A…
- CVE-2005-3923NetObjects Fusion 9 (NOF9) allows remote attackers to obtain…
- CVE-2005-3924SQL injection vulnerability in themes/kategorie/index.php in…
- CVE-2005-3925Multiple SQL injection vulnerabilities in Central Manchester…
- CVE-2005-3926Direct static code injection vulnerability in error.php in G…
- CVE-2005-3927Multiple directory traversal vulnerabilities in GuppY 4.5.9 …
Are you affected by CVE-2005-3921?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
