Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2011-2544

EPSS 4.22% · P89
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2011-2544

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Cross-site scripting (XSS) vulnerability in the web interface in Cisco TelePresence System MXP Series F9.1 and earlier allows remote authenticated users to inject arbitrary web script or HTML via a crafted Call ID, as demonstrated by resultant cross-site request forgery (CSRF) attacks that change passwords or cause a denial of service, aka Bug ID CSCtq46488.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Cisco TelePresence Endpoint HTML注入漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Cisco TelePresence是美国思科(Cisco)公司的一套被称为“网真”系统的视频会议解决方案。该方案提供音频、视频空间等组件,可为远程参会者提供一个“面对面”的虚拟会议室效果。Cisco TelePresence Endpoint是其中的终端服务。 由于H.323 ID或SIP Display Name字段的灵活性以及无法正确验证用户输入,Cisco TelePresence Endpoint在实现上存在HTML注入漏洞,远程攻击者可利用HTML注入漏洞在受影响浏览器中执行任意脚本代码,窃取
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2011-2544

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2011-2544

登录查看更多情报信息。

Same Patch Batch · n/a · 2011-09-23 · 68 CVEs total

CVE-2011-3738Feng Office敏感信息泄露漏洞
CVE-2011-3756MicroBlog敏感信息泄露漏洞
CVE-2011-3757Moodle敏感信息泄露漏洞
CVE-2011-3755MantisBT敏感信息泄露漏洞
CVE-2011-3744HTML Purifier敏感信息泄露漏洞
CVE-2011-3743Hesk敏感信息泄露漏洞
CVE-2011-3742HelpCenter Live敏感信息泄露漏洞
CVE-2011-3741HelpCenter Live敏感信息泄露
CVE-2011-3740HelpCenter Live敏感信息泄露漏洞
CVE-2011-3739Freeway敏感信息泄露漏洞
CVE-2011-3745HycusCMS敏感信息泄露漏洞
CVE-2011-3737eyeOS敏感信息泄露漏洞
CVE-2011-3736ExoPHPDesk敏感信息泄露漏洞
CVE-2011-3735Escort Agency CMS敏感信息泄露漏洞
CVE-2011-3734Energine敏感信息泄露漏洞
CVE-2011-3733Elgg敏感信息泄露漏洞
CVE-2011-3732eggBlog敏感信息泄露漏洞
CVE-2011-3731e107敏感信息泄露漏洞
CVE-2011-3730Drupal敏感信息泄露漏洞
CVE-2011-3729dotproject敏感信息泄露漏洞

Showing top 20 of 68 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2011-2544

No comments yet


Leave a comment