Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

HTTP:XSS:CISCO-SESM

Severity

High

Recommended

No

Recommended Action

Drop

Category

HTTP

Keywords

Cisco Subscriber Edge Services Manager Cross-Site Scripting

Release Date

2013/06/11

Update Number

2271

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

HTTP: Cisco Subscriber Edge Services Manager Cross-Site Scripting


This signature detects attempts to exploit a cross-site scripting vulnerability in Cisco Subscriber. An attacker can leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site.

Extended Description

Cisco Subscriber Edge Services Manager is prone to a cross-site scripting vulnerability and an HTML-injection vulnerability because it fails to sufficiently sanitize user-supplied data. Attacker-supplied HTML or JavaScript code could run in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials and to control how the site is rendered to the user; other attacks are also possible. We don't know which versions of Subscriber Edge Services Manager are affected. We will update this BID as more information emerges.

Affected Products

  • Cisco Subscriber Edge Services Manager (SESM)

References

  • BugTraq: 34454
  • CVE: CVE-2009-1287

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out