{"schema_version":"public-product-v1.1","generated_at":"2026-07-21T10:40:37Z","exposure_verdict":"not_assessed","verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure.","advisory":{"id":"Cisco-SA-20110518-CVE-2011-0961","slug":"cisco-sa-20110518-cve-2011-0961","vendor":"Cisco","title":"CiscoWorks Common Services Framework Help Servlet Cross-Site Scripting Vulnerability","summary":"CiscoWorks Common Services contains a cross-site scripting vulnerability that could allow an unauthenticated, remote attacker to conduct cross-site scripting attacks. The vulnerability is due to improper validation of malformed user input supplied via URL parameters to the affected application.&nbsp; An unauthenticated, remote attacker could exploit this vulnerability by convincing a user to view a malicious link.&nbsp; If successful, the attacker could execute arbitrary script or HTML code in the user's browser in the security context of the affected site. Exploit code is available. Cisco has confirmed this vulnerability and has released updated software. To exploit this vulnerability, an attacker must convince a user to follow a malicious link.&nbsp; The attacker may provide links in e-mail or instant messages. Functional exploit code that demonstrates the ability to execute malicious script in a user's browser is publicly available. This vulnerability was discovered and reported to Cisco Systems by Brett Gervasoni of Sense of Security.","severity":"Medium","published_at":"2011-05-18T13:17:48Z","updated_at":"2011-05-18T13:17:48Z","source_url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/Cisco-SA-20110518-CVE-2011-0961","csaf_url":"https://sec.cloudapps.cisco.com/security/center/contentjson/CiscoSecurityAdvisory/Cisco-SA-20110518-CVE-2011-0961/csaf/Cisco-SA-20110518-CVE-2011-0961.json","exposure_verdict":"not_assessed","verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure."},"freshness":{"last_source_refreshed_at":"2026-07-21T05:16:34Z","latest_source_refresh_at":"2026-07-21T05:16:34Z","oldest_source_refresh_at":"2026-07-21T03:00:03Z","all_sources_fresh":true,"sources":[{"source":"cisco_advisories","label":"Cisco advisories","last_success_at":"2026-07-21T03:00:03Z","stale":false},{"source":"cisco_csaf","label":"Cisco CSAF","last_success_at":"2026-07-21T05:14:24Z","stale":false},{"source":"nvd_cves","label":"NVD CVEs","last_success_at":"2026-07-21T05:16:30Z","stale":false},{"source":"cisa_kev","label":"CISA KEV","last_success_at":"2026-07-21T05:16:31Z","stale":false},{"source":"first_epss","label":"EPSS","last_success_at":"2026-07-21T05:16:34Z","stale":false}]},"summary":{"cve_count":1,"visible_product_count":1,"public_evidence_count":1,"kev_count":0,"highest_epss":0.05154},"cves":[{"id":"CVE-2011-0961","kev":false,"epss":{"score":0.05154,"percentile":0.91509,"score_date":"2026-07-20","updated_at":"2026-07-21T05:16:32Z"}}],"public_evidence":[{"product":{"name":"CiscoWorks Common Services (CS)","slug":"ciscoworks-common-services-cs","vendor":"Cisco"},"cve":{"id":"CVE-2011-0961"},"evidence_type":"structured_affected","evidence_label":{"scope":"CSAF product evidence","label":"product_status known affected"},"evidence_source":"Cisco CSAF","source":"Cisco CSAF","source_document_fetched_at":"2026-07-20T05:34:47Z","csaf_status":"known_affected","csaf_product_status":"known_affected","csaf_product_status_path":"vulnerabilities[].product_status.known_affected","raw_product_name":"CiscoWorks Common Services (CS)","exposure_verdict":"not_assessed","verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure.","exposure_verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure.","kev":false,"epss":{"score":0.05154,"score_date":"2026-07-20","updated_at":"2026-07-21T05:16:32Z"},"published_at":"2011-05-18T13:17:48Z","updated_at":"2011-05-18T13:17:48Z","advisory_updated_at":"2011-05-18T13:17:48Z","source_url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/Cisco-SA-20110518-CVE-2011-0961","row_display_order":1}]}