Cross-site scripting (XSS) vulnerability in cwhp/device.center.do in the Help servlet in Cisco CiscoWorks Common Services 3.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the device parameter, aka Bug ID CSCto12704.
https://exchange.xforce.ibmcloud.com/vulnerabilities/67523
http://tools.cisco.com/security/center/viewAlert.x?alertId=23088