Short Name |
HTTP:XSS:CISCO-SESM |
---|---|
Severity |
High |
Recommended |
No |
Recommended Action |
Drop |
Category |
HTTP |
Keywords |
Cisco Subscriber Edge Services Manager Cross-Site Scripting |
Release Date |
2013/06/11 |
Update Number |
2271 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+ |
This signature detects attempts to exploit a cross-site scripting vulnerability in Cisco Subscriber. An attacker can leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site.
Cisco Subscriber Edge Services Manager is prone to a cross-site scripting vulnerability and an HTML-injection vulnerability because it fails to sufficiently sanitize user-supplied data. Attacker-supplied HTML or JavaScript code could run in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials and to control how the site is rendered to the user; other attacks are also possible. We don't know which versions of Subscriber Edge Services Manager are affected. We will update this BID as more information emerges.