VULNERABILIDAD. Cisco Subscriber Edge Services Manager Cross Site Scripting And HTML Injection Vulnerabilities

Cisco Subscriber Edge Services Manager is prone to an unspecified cross-site scripting vulnerability and an unspecified HTML-injection vulnerability because it fails to sufficiently sanitize user-supplied data.

Attacker-supplied HTML or JavaScript code could run in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials and to control how the site is rendered to the user; other attacks are also possible.

We don’t know which versions of Subscriber Edge Services Manager are affected. We will update this BID as more information emerges.

Published:       Apr 09 2009 12:00AM
Updated:         Apr 09 2009 08:16PM

REFERENCIA

fuente: securityfocus.com

cisco

Anuncios

Responder

Por favor, inicia sesión con uno de estos métodos para publicar tu comentario:

Logo de WordPress.com

Estás comentando usando tu cuenta de WordPress.com. Cerrar sesión / Cambiar )

Imagen de Twitter

Estás comentando usando tu cuenta de Twitter. Cerrar sesión / Cambiar )

Foto de Facebook

Estás comentando usando tu cuenta de Facebook. Cerrar sesión / Cambiar )

Google+ photo

Estás comentando usando tu cuenta de Google+. Cerrar sesión / Cambiar )

Conectando a %s