Multiple Alcatel-Lucent OmniTouch Products CVE-2013-4653 Cross Site Scripting Vulnerability
BID:60902
Info
Multiple Alcatel-Lucent OmniTouch Products CVE-2013-4653 Cross Site Scripting Vulnerability
| Bugtraq ID: | 60902 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-4653 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 02 2013 12:00AM |
| Updated: | Jul 02 2013 12:00AM |
| Credit: | Giovanni Del Vecchio of SmartNet |
| Vulnerable: |
Alcatel-Lucent OmniTouch 8400 Instant Communications Suite 6.5.000.105.B Alcatel-Lucent OmniTouch 8400 Instant Communications Suite 6.5 Alcatel-Lucent OmniTouch 8400 Instant Communications Suite 6.1 Patch 102a |
| Not Vulnerable: | |
Discussion
Multiple Alcatel-Lucent OmniTouch Products CVE-2013-4653 Cross Site Scripting Vulnerability
Multiple Alcatel-Lucent OmniTouch products are prone to a cross-site scripting vulnerability.
An attacker could leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This could allow the attacker to steal cookie-based authentication credentials and launch other attacks.
The following products are vulnerable:
Omnitouch 8660 My Teamwork versions prior to 6.7
Omnitouch 8670 Automated Message Delivery System versions prior to 6.7
Omnitouch 8460 Advanced Communication Server versions prior to 9.1
OmniTouch 8400 Instant Communications Suite versions prior to 6.7.3
Multiple Alcatel-Lucent OmniTouch products are prone to a cross-site scripting vulnerability.
An attacker could leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This could allow the attacker to steal cookie-based authentication credentials and launch other attacks.
The following products are vulnerable:
Omnitouch 8660 My Teamwork versions prior to 6.7
Omnitouch 8670 Automated Message Delivery System versions prior to 6.7
Omnitouch 8460 Advanced Communication Server versions prior to 9.1
OmniTouch 8400 Instant Communications Suite versions prior to 6.7.3
Exploit / POC
Multiple Alcatel-Lucent OmniTouch Products CVE-2013-4653 Cross Site Scripting Vulnerability
Attackers can exploit this issue by enticing an unsuspecting victim to follow a malicious URI.
Attackers can exploit this issue by enticing an unsuspecting victim to follow a malicious URI.
Solution / Fix
Multiple Alcatel-Lucent OmniTouch Products CVE-2013-4653 Cross Site Scripting Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.