Cisco CallManager Cross-Site Scripting Vulnerability
BID:18504
CVE-2006-3109 |Info
Cisco CallManager Cross-Site Scripting Vulnerability
| Bugtraq ID: | 18504 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 19 2006 12:00AM |
| Updated: | Jun 20 2006 08:10PM |
| Credit: | Jake Reynolds of FishNet Security is credited with the discovery of this vulnerability. |
| Vulnerable: |
Cisco Call Manager 4.1 (3)SR2 Cisco Call Manager 4.1 (3)SR1 Cisco Call Manager 4.1 (3)ES32 Cisco Call Manager 4.1 (3)ES24 Cisco Call Manager 4.1 (3)ES07 Cisco Call Manager 4.1 (2)ES55 Cisco Call Manager 4.1 (2)ES50 Cisco Call Manager 4.1 (2)ES33 Cisco Call Manager 4.0 (2a)SR2c Cisco Call Manager 4.0 (2a)SR2b Cisco Call Manager 4.0 (2a)ES62 Cisco Call Manager 4.0 (2a)ES56 Cisco Call Manager 4.0 (2a)ES40 Cisco Call Manager 4.0 Cisco Call Manager 3.3 (5)SR1a Cisco Call Manager 3.3 (5)ES30 Cisco Call Manager 3.3 (5)ES24 Cisco Call Manager 3.3 (5) Cisco Call Manager 3.3 (4)ES25 Cisco Call Manager 3.3 (3)ES61 Cisco Call Manager 3.3 (3) Cisco Call Manager 3.3 Cisco Call Manager 3.2 Cisco Call Manager 3.1 (3a) Cisco Call Manager 3.1 (2) Cisco Call Manager 3.1 |
| Not Vulnerable: |
Cisco Call Manager 4.3(1) Cisco Call Manager 4.2(3) Cisco Call Manager 4.1(3)SR4 Cisco Call Manager 3.3(5)SR3 |
Discussion
Cisco CallManager Cross-Site Scripting Vulnerability
Cisco CallManager is prone to a cross-site scripting vulnerability. This issue is due to a failure in the web-interface to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting administrative user in the context of the affected site. This may help the attacker launch other attacks.
Cisco CallManager is prone to a cross-site scripting vulnerability. This issue is due to a failure in the web-interface to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting administrative user in the context of the affected site. This may help the attacker launch other attacks.
Exploit / POC
Cisco CallManager Cross-Site Scripting Vulnerability
This issue can be exploited through a web client.
The following proof-of-concept URIs are available:
This issue can be exploited through a web client.
The following proof-of-concept URIs are available:
Solution / Fix
Cisco CallManager Cross-Site Scripting Vulnerability
Solution:
Cisco has released an advisory to address this issue. Fixes are reportedly forthcoming. Please see the referenced advisory for more information.
Solution:
Cisco has released an advisory to address this issue. Fixes are reportedly forthcoming. Please see the referenced advisory for more information.
References
Cisco CallManager Cross-Site Scripting Vulnerability
References:
References:
- CallManager Product Page (Cisco)
- Cisco Security Response: Input Validation/Output Encoding Vulnerabilities in Cis (Cisco)
- Input Validation/Output Encoding Vulnerabilities in Cisco CallManager Allow Scri (Jake Reynolds)
- Input Validation/Output Encoding Vulnerabilities in Cisco CallManager Allow Scri ("Reynolds, Jake"