Cisco MediaSense CVE-2014-0671 Open Redirection Vulnerability
BID:65055
Info
Cisco MediaSense CVE-2014-0671 Open Redirection Vulnerability
| Bugtraq ID: | 65055 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-0671 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 21 2014 12:00AM |
| Updated: | Jan 24 2014 12:32AM |
| Credit: | Cisco |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Cisco MediaSense CVE-2014-0671 Open Redirection Vulnerability
Cisco MediaSense is prone to a cross-site scripting vulnerability.
An attacker can leverage this issue by constructing a crafted URI and enticing a user to follow it. When an unsuspecting victim follows the link, they may be redirected to an attacker-controlled site; this may aid in phishing attacks. Other attacks are possible.
This issue is being tracked by Cisco Bug ID CSCum16749.
Cisco MediaSense is prone to a cross-site scripting vulnerability.
An attacker can leverage this issue by constructing a crafted URI and enticing a user to follow it. When an unsuspecting victim follows the link, they may be redirected to an attacker-controlled site; this may aid in phishing attacks. Other attacks are possible.
This issue is being tracked by Cisco Bug ID CSCum16749.
Exploit / POC
Cisco MediaSense CVE-2014-0671 Open Redirection Vulnerability
Attackers can exploit this issue by enticing an unsuspecting victim to follow a malicious URI.
Attackers can exploit this issue by enticing an unsuspecting victim to follow a malicious URI.
Solution / Fix
Cisco MediaSense CVE-2014-0671 Open Redirection Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].