funsec mailing list archives

Cisco Secure ACS for Unix Cross-Site Scripting Vulnerability


From: "Fergie" <fergdawg () netzero net>
Date: Fri, 16 Jun 2006 16:55:25 GMT

Via Secunia:
http://secunia.com/advisories/20699/

[snip]

Description:
A vulnerability has been reported in Cisco Secure ACS for Unix, which
can be exploited by malicious people to conduct cross-site scripting
attacks.

Input passed to specified parameters in LogonProxy.cgi is not properly
sanitised before being returned to the user. This can be exploited to
execute arbitrary HTML and script code in a user's browser session in
context of an affected site.

The vulnerability has been reported in Cisco Secure ACS for Unix. Cisco
Secure ACS for Windows and Cisco Secure ACS Solution Engine are
reportedly not affected.

Solution:
Apply patch.
http://www.cisco.com/pcgi-bin/tablebuild.pl/cspatchunix-3des

Provided and/or discovered by:
The vendor credits Thomas Liam Romanis and Fujitsu Services Limited.

Original Advisory:
Cisco:
http://www.cisco.com/warp/public/707/cisco-sr-20060615-acs.shtml

[snip]

- ferg


--
"Fergie", a.k.a. Paul Ferguson
 Engineering Architecture for the Internet
 fergdawg () netzero net or fergdawg () sbcglobal net
 ferg's tech blog: http://fergdawg.blogspot.com/


_______________________________________________
Fun and Misc security discussion for OT posts.
https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
Note: funsec is a public and open mailing list.


Current thread: