网管联盟 | 网管论坛 | 网管u家 | 网管博客 | 网管软件 | 网管求职 | 小游戏 | 网管搜索 | 网管原创 | 网管聚合 | 网管读摘 | 网管焦点 | 世界素材 | 会员投稿 | 会员中心 
中国网管联盟
Windows Linux Cisco 网络技术 数据库 黑客攻防 DotNet Java PHP 认证 新闻资讯 服务器 存储资讯 网络设备 网管学堂 技术专题 焦点 网吧频道
 当前位置: > bitsCN.com > 网络攻防 > 黑客技术 > Exploit > Cisco Unified MeetingPlace Web Conferencing Input Validation Hole Permits Cross-  

Cisco Unified MeetingPlace Web Conferencing Input Validation Hole Permits Cross-

2007-11-10  作者:bitsCN整理  来源:中国网管联盟  点评 投稿 收藏

Advisory:  Cisco Security Advisory
Version(s): 5.3 and prior versions, 5.4, 6.0
Description:  A vulnerability was reported in Cisco Unified MeetingPlace Web Conferencing. A remote user can conduct cross-site scripting attacks.
网管朋友网www_bitscn_net

The login screen does not properly filter HTML code from user-supplied input before displaying the input. A remote user can create a specially crafted URL that, when loaded by a target user, will cause arbitrary scripting code to be executed by the target user's browser. The code will originate from the site running the Cisco Unified MeetingPlace software and will run in the security context of that site. As a result, the code will be able to access the target user's cookies (including authentication cookies), if any, associated with the site, access data recently submitted by the target user via web form to the site, or take actions on the site acting as the target user.

网管朋友网www_bitscn_net

The FirstName or LastName parameters are affected.

网管联盟bitsCN@com

Cisco has assigned Cisco bug ID CSCsk17122 to this vulnerability. 网管网www.bitscn.com

Joren McReynolds reported this vulnerability.
Impact:  A remote user can access the target user's cookies (including authentication cookies), if any, associated with the site running the Cisco Unified MeetingPlace software, access data recently submitted by the target user via web form to the site, or take actions on the site acting as the target user.
Solution:  The vendor has issued fixed versions (5.4.156.2E, 6.0.244.1A). No fix is available for version 5.3 or prior versions.

中国网管联盟bitsCN.com

The Cisco advisory is available at: 中国网管联盟bitsCN.com

http://www.cisco.com/warp/public/707/cisco-sr-20071107-mp.shtml
Vendor URL:  www.cisco.com/warp/public/707/cisco-sr-20071107-mp.shtml (Links to External Site)
Cause:  Input validation error

网管u家www.bitscn.net

Message History:   None.

网管有家bitscn.net

  网管网www.bitscn.com

 

网管u家bitscn.net

TAGs     the   user   target   Cisco   site   to   The   or   access   cookies      
 上一篇:Xpdf Bugs in streams and t1lib Let Remote Users Execute Arbitrary Code   下一篇:Microsoft DebugView 'Dbgv.sys' Module Lets Local Users Gain Kernel Lev
Cisco Unified MeetingPlace Web Conferencing Input Validation Hole Permits Cross- 评论:
loading.. 评论加载中…
评论:请自觉遵守互联网相关政策法规,评论不得超过250字。

验证码: 注册用户
本类热门排行:
最新推荐文章:
网管论坛交流: