Avaya IP Office Customer Call Reporter Cross Site Scripting and Frame Injection Vulnerabilities
BID:62297
Info
Avaya IP Office Customer Call Reporter Cross Site Scripting and Frame Injection Vulnerabilities
| Bugtraq ID: | 62297 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 29 2013 12:00AM |
| Updated: | Jul 29 2013 12:00AM |
| Credit: | MustLive |
| Vulnerable: |
Avaya IP Office Customer Call Reporter 9.0 Avaya IP Office Customer Call Reporter 8.0.9.13 |
| Not Vulnerable: | |
Discussion
Avaya IP Office Customer Call Reporter Cross Site Scripting and Frame Injection Vulnerabilities
Avaya IP Office Customer Call Reporter is prone to a cross-site scripting vulnerability and a frame-injection vulnerability.
An attacker may exploit these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, steal cookie-based authentication credentials, monitor legitimate web users activity and perform unauthorized actions.
Avaya IP Office Customer Call Reporter 8.0.9.13 and 9.0 are vulnerable.
Avaya IP Office Customer Call Reporter is prone to a cross-site scripting vulnerability and a frame-injection vulnerability.
An attacker may exploit these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, steal cookie-based authentication credentials, monitor legitimate web users activity and perform unauthorized actions.
Avaya IP Office Customer Call Reporter 8.0.9.13 and 9.0 are vulnerable.
Exploit / POC
Avaya IP Office Customer Call Reporter Cross Site Scripting and Frame Injection Vulnerabilities
An attacker can frame-injection issue using a web browser. To exploit cross-site scripting issue an attacker must entice an unsuspecting victim into following a malicious URI or visiting a malicious website.
The following example URIs are available:
http://www.example.com/CCRWebClient/Help/en-US/index.htm?//websecurity.com.ua
http://www.example.com/CCRWebClient/Help/en-US/index.htm?//websecurity.com.ua/webtools/xss_r2.html
An attacker can frame-injection issue using a web browser. To exploit cross-site scripting issue an attacker must entice an unsuspecting victim into following a malicious URI or visiting a malicious website.
The following example URIs are available:
http://www.example.com/CCRWebClient/Help/en-US/index.htm?//websecurity.com.ua
http://www.example.com/CCRWebClient/Help/en-US/index.htm?//websecurity.com.ua/webtools/xss_r2.html
Solution / Fix
Avaya IP Office Customer Call Reporter Cross Site Scripting and Frame Injection Vulnerabilities
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Avaya IP Office Customer Call Reporter Cross Site Scripting and Frame Injection Vulnerabilities
References:
References:
- Avaya Home Page (Avaya)
- Vulnerabilities in Avaya IP Office Customer Call Reporter (Full Disclosure)
- Vulnerabilities in Avaya IP Office Customer Call Reporter (MustLive)