In association with heise online

19 March 2007, 13:25

XSS vulnerability in Cisco's online help system

  • Twitter
  • Facebook
  • submit to slashdot
  • StumbleUpon
  • submit to reddit

In a security response, Cisco has released details of a cross-site scripting vulnerability in its online help, included in numerous Cisco software products. The bug lies in the search function, PreSearch.html / PreSearch.class, which fails to filter the content entered. Using a prepared link, an attacker could execute JavaScript in the user's web browser if the user follows the particular link. The vendor does not elucidate what the consequences of this might be for the relevant software.

Numerous products are affected, including the VPN client, IP Communicator, CallManager and Secure Access Control Server. The security response from Cisco provides a full overview. No update is available - Cisco suggests deleting or renaming the PreSearch.html or PreSearch.class files.

See also:


Print Version | Send by email | Permalink:

  • July's Community Calendar

The H Open

The H Security

The H Developer

The H Internet Toolkit