Cisco cross-origin localStorage XSS PoC

For authorized security testing only. This page writes a benign javascript:alert(document.domain) entry to Cisco's Recently Viewed Products list through the vulnerable cross-origin localStorage bridge.

This temporarily replaces the browser's Cisco Recently Viewed Products history. Use the cleanup button when finished.

  1. This page automatically attempts to plant the alert entry. Allow the popup if the browser asks.
  2. If the browser blocks the automatic popup, allow popups and use the retry button that appears.
  3. After the status says the entry was planted, open Cisco Support.
  4. Under Recently Viewed Products, click the planted PoC entry.
  5. The dialog should display www.cisco.com.

Open Cisco Support

Preparing automatic planting attempt...