Vulnerabilities > CVE-2006-4909 - Cross-Site Scripting vulnerability in Cisco Guard Ddos Mitigation Appliance 5.1(5)

047910
CVSS 2.6 - LOW
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
high complexity
cisco

Summary

Cross-site scripting (XSS) vulnerability in Cisco Guard DDoS Mitigation Appliance before 5.1(6), when anti-spoofing is enabled, allows remote attackers to inject arbitrary web script or HTML via certain character sequences in a URL that are not properly handled when the appliance sends a meta-refresh.

Vulnerable Configurations

Part Description Count
Hardware
Cisco
2