Cisco BBSM Captive Portal 'AccesCodeStart.asp' Cross-Site Scripting Vulnerability
BID:29191
Info
Cisco BBSM Captive Portal 'AccesCodeStart.asp' Cross-Site Scripting Vulnerability
| Bugtraq ID: | 29191 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-2165 |
| Remote: | Yes |
| Local: | No |
| Published: | May 13 2008 12:00AM |
| Updated: | May 14 2008 06:05PM |
| Credit: | Brad Antoniewicz |
| Vulnerable: |
Cisco Building Broadband Service Manager (BBSM) 5.3 |
| Not Vulnerable: | |
Discussion
Cisco BBSM Captive Portal 'AccesCodeStart.asp' Cross-Site Scripting Vulnerability
Cisco BBSM (Building Broadband Service Manager) is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Cisco BBSM 5.3 is vulnerable; other versions may also be affected.
Cisco BBSM (Building Broadband Service Manager) is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Cisco BBSM 5.3 is vulnerable; other versions may also be affected.
Exploit / POC
Cisco BBSM Captive Portal 'AccesCodeStart.asp' Cross-Site Scripting Vulnerability
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
The following proof-of-concept URI is available:
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
The following proof-of-concept URI is available:
Solution / Fix
Cisco BBSM Captive Portal 'AccesCodeStart.asp' Cross-Site Scripting Vulnerability
Solution:
The vendor has released an update. Please see the references for more information.
Solution:
The vendor has released an update. Please see the references for more information.
References
Cisco BBSM Captive Portal 'AccesCodeStart.asp' Cross-Site Scripting Vulnerability
References:
References:
- Cisco BBSM Homepage (Cisco)
- Cisco Homepage (Cisco)
- Re: Cisco BBSM Captive Portal Cross-site Scripting (Eloy Paris
)