漏洞信息详情
Cisco CallManager 多个跨站脚本攻击漏洞
- CNNVD编号:CNNVD-200606-379
- 危害等级: 中危
- CVE编号:
CVE-2006-3109
- 漏洞类型:
跨站脚本
- 发布时间:
2006-06-20
- 威胁类型:
远程
- 更新时间:
2006-06-22
- 厂 商:
cisco - 漏洞来源:
Jake Reynolds of F… -
漏洞简介
Cisco CallManager 3.3 3.3(5)SR3之前的3.3 版本, 4.1(3)SR4之前的4.1 版本, 4.2(3)之前的4.2版本,以及4.3(1)之前的4.3版本存在跨站脚本攻击(XSS)漏洞。远程攻击者可以借助(1)ccmadmin/phonelist.asp中的pattern参数和(2)ccmuser/logon.asp中的任意参数,注入任意Web脚本或HTML,又称CSCsb68657。
漏洞公告
Cisco已经发布公告以解决此问题。据称修复程序即将发布。更多信息,请参见引用的公告。
参考网址
来源: CISCO
名称: 20060619 Cisco Response to: Input Validation/Output Encoding Vulnerabilities in Cisco CallManager Allow Script Injection Attacks
来源: SECTRACK
名称: 1016328
链接:http://securitytracker.com/id?1016328
来源: BID
名称: 18504
链接:http://www.securityfocus.com/bid/18504
来源: BUGTRAQ
名称: 20060619 Input Validation/Output Encoding Vulnerabilities in Cisco CallManager Allow Script Injection Attacks
链接:http://www.securityfocus.com/archive/1/archive/1/437757/100/0/threaded
来源: MISC
链接:http://www.fishnetsecurity.com/csirt/disclosure/cisco/Cisco+CallManager+XSS+Advisory.htm
来源: FULLDISC
名称: 20060619 Input Validation/Output Encoding Vulnerabilities in Cisco CallManager Allow Script Injection Attacks
链接:http://lists.grok.org.uk/pipermail/full-disclosure/2006-June/047015.html
来源: XF
名称: cisco-callmanager-web-xss(27225)
链接:http://xforce.iss.net/xforce/xfdb/27225
来源: OSVDB
名称: 26652
来源: OSVDB
名称: 26651
来源: VUPEN
名称: ADV-2006-2443
链接:http://www.frsirt.com/english/advisories/2006/2443
来源: SREASON
名称: 1114
链接:http://securityreason.com/securityalert/1114
来源: SECUNIA
名称: 20735
链接:http://secunia.com/advisories/20735
来源: FULLDISC
名称: 20060620 Re: Input Validation/Output Encoding Vulnerabilities in Cisco CallManager Allow Script Injection Attacks
链接:http://lists.grok.org.uk/pipermail/full-disclosure/2006-June/047019.html