Cisco Unity Input Validation Hole Permits Cross-Site Scripting Attacks
|
|
SecurityTracker Alert ID: 1021012
|
|
SecurityTracker URL: http://securitytracker.com/id?1021012
|
|
CVE Reference: CVE-2008-4542
(Links to External Site)
|
Updated: Oct 14 2008
|
Original Entry Date: Oct 8 2008
|
Impact: Disclosure of authentication information, Disclosure of user information, Execution of arbitrary code via network, Modification of user information
|
Vendor Confirmed: Yes
|
Advisory: Cisco Security Advisory
|
Version(s): 4.x, 5.x, 7.x
|
Description: A vulnerability was reported in Cisco Unity. A remote authenticated administrator can conduct cross-site scripting attacks.
The system does not properly filter HTML code from user-supplied input before displaying the input. A remote authenticated administrative
user can store a specially crafted data entry. Then, when the underlying data is viewed by a target administrative user, arbitrary
scripting code will be executed by the target user's browser. The code will originate from the Cisco Unity device and will run
in the security context of that site. As a result, the code will be able to access the target user's cookies (including authentication
cookies), if any, associated with the site, access data recently submitted by the target user via web form to the site, or take
actions on the site acting as the target user.
Cisco has assigned Cisco Bug ID CSCsr86345 to this vulnerability.
The original
advisory is available at:
http://www.voipshield.com/research-details.php?id=127
VoIPshield Systems reported this vulnerability.
|
Impact: A remote authenticated administrative user can access the target administrative user's cookies (including authentication cookies),
if any, associated with the Cisco Unity device, access data recently submitted by the target user via web form to the device, or
take actions on the device acting as the target user.
|
Solution: No solution was available at the time of this entry.
The vendor plans to issued fixed versions (4.2(1)ES162, 5.0(1)ES56, 7.0(2)ES8).
The
vendor's advisory is available at:
http://www.cisco.com/warp/public/707/cisco-sr-20081008-unity.shtml
|
Vendor URL: www.cisco.com/warp/public/707/cisco-sr-20081008-unity.shtml (Links to External Site)
|
Cause: Input validation error
|
|
Message History:
None.
|
Source Message Contents
|
Date: Wed, 8 Oct 2008 17:09:28 -0400
Subject: Cisco Security Response: VoIPshield Reported Vulnerabilities in Cisco Unity Server
|
http://www.cisco.com/warp/public/707/cisco-sr-20081008-unity.shtml
|
|