Cisco

Cisco Security Response: CiscoWorks Server XSS Vulnerability

06 december, 2007

Cisco Security Response: CiscoWorks Server XSS Vulnerability
Document ID: 100240
http://www.cisco.com/warp/public/707/cisco-sr-20071205-cw.shtml
Revision 1.0
For Public Release 2007 December 05 1600 UTC (GMT)

--------------------------------------------------------------------------------

Please provide your feedback on this document.

--------------------------------------------------------------------------------

Contents
Cisco Response
Additional Information
Revision History
Cisco Security Procedures


--------------------------------------------------------------------------------

Cisco Response
This is the Cisco PSIRT response to an issue that was discovered and reported to Cisco by David Lewis of Liquidmatrix.org regarding a cross-site scripting (XSS) vulnerability in CiscoWorks Server login page.

The original report is available at the following link: http://www.liquidmatrix.org/blog/2007/12/05/advisory-cross-site-scripting-in-ciscoworks/.

We greatly appreciate the opportunity to work with researchers on security vulnerabilities and welcome the opportunity to review and assist in product reports.

This vulnerability is documented in Cisco bug ID CSCsk69289 ( registered customers only) .

This Cisco Security Response is posted at the following link: http://www.cisco.com/warp/public/707/cisco-sr-20071205-cw.shtml.

This vulnerability has been assigned CVE ID CVE-2007-5582.

Additional Information
CiscoWorks Common Services (CS) provides the foundation of application infrastructure for all existing CiscoWorks network management solutions to share a common model for data storage, user login, user role definitions, user access privileges, and security protocols.

CS is vulnerable to Cross Site Scripting (XSS) attacks from the CiscoWorks Server login page, http://server-name:portnumber. In both Windows and Solaris, the port numbers are 1741 for normal access, and the secure port number is 443. Both the Windows and Solaris versions of the Cisco Works Server login page are affected.

When this XSS vulnerability is exploited, malicious code or script is embedded within the URL and associated with an unsuccessful login attempt page refresh.

The malicious code typically takes the form of a script that is embedded within the URL of a link. The malicious code may also be stored on the vulnerable server or a malicious website. An attacker could try to convince an unsuspecting user to follow a malicious link to a vulnerable CiscoWorks server that injects (reflects) the malicious code into the user's browser.

The following versions of CiscoWorks Common Services for both Solaris and Windows operating systems are affected by this vulnerability:

CiscoWorks Common Services 3.0.x

CiscoWorks Common Services 3.1

Prior to CiscoWorks Common Services 3.0, the product was titled CiscoWorks Common Management Foundation (CMF). CMF is not affected by this vulnerability.

CiscoWorks products that do not use CiscoWorks Common Services are not affected by this vulnerability.

Workarounds
There are no known workarounds for this vulnerability. Cisco recommends applying a point patch to address the vulnerability. The point patch can be downloaded from Cisco.com for both Solaris and Windows Operating Systems at: http://www.cisco.com/pcgi-bin/tablebuild.pl/cw2000-cd-one ( registered customers only) .

For additional information on XSS attacks and the methods used to exploit these vulnerabilities, please refer to the Cisco Applied Mitigation Bulletin "Understanding Cross-Site Scripting (XSS) Threat Vectors", which is available at the following link:

http://www.cisco.com/warp/public/707/cisco-amb-20060922-understanding-xss.shtml

THIS DOCUMENT IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. CISCO RESERVES THE RIGHT TO CHANGE OR UPDATE THIS DOCUMENT AT ANY TIME.

Revision History
Revision 1.0
2007-December-05
Initial public release

CVE-2011-4861

The modbus_125_handler function in the Schneider Electric Quantum Ethernet Module on the NOE 771 device (aka the Quantum 140NOE771* module) allows remote attackers to install arbitrary firmware updates via a MODBUS 125 function code to TCP port 50 ...

17 december, 2011

CVE-2011-4860

The ComputePassword function in the Schneider Electric Quantum Ethernet Module on the NOE 771 device (aka the Quantum 140NOE771* module) generates the password for the fwupgrade account by performing a calculation on the MAC address, which makes i ...

17 december, 2011

CVE-2011-4859

The Schneider Electric Quantum Ethernet Module, as used in the Quantum 140NOE771* and 140CPU65* modules, the Premium TSXETY* and TSXP57* modules, the M340 BMXNOE01* and BMXP3420* modules, and the STB DIO STBNIC2212 and STBNIP2* modules, uses hardcoded pas ...

17 december, 2011

CVE-2011-4857

Heap-based buffer overflow in the in_mod.dll plugin in Winamp before 5.623 allows remote attackers to execute arbitrary code via crafted song message data in an Impulse Tracker (IT) file.   NOTE: some of these details are obtained from ...

16 december, 2011

CVE-2011-4856

The Control Panel in Parallels Plesk Panel 10.4.4_buil d20111103.1 sends incorrect Content-Type headers for certain resources, which might allow remote attackers to have an unspecified impact by leveraging an interpretation conflict involving admin/healt ...

16 december, 2011

CVE-2011-4855

The Control Panel in Parallels Plesk Panel 10.4.4_buil d20111103.1 omits the Content-Type header's charset parameter for certain resources, which might allow remote attackers to have an unspecified impact by leveraging an interpretation conflict invo ...

16 december, 2011

CVE-2011-4854

The Control Panel in Parallels Plesk Panel 10.4.4_buil d20111103.1 does not ensure that Content-Type HTTP headers match the corresponding Content-Type data in HTML META elements, which might allow remote attackers to have an unspecified impact by leverag ...

16 december, 2011

CVE-2011-4853

The Control Panel in Parallels Plesk Panel 10.4.4_buil d20111103.1 includes an RFC 1918 IP address within a web page, which allows remote attackers to obtain potentially sensitive information by reading this page, as demonstrated by smb/user/list-dat a/i ...

16 december, 2011

CVE-2011-4852

The Control Panel in Parallels Plesk Panel 10.4.4_buil d20111103.1 generates web pages containing external links in response to GET requests with query strings for enterprise/mo bile-monitor/ and certain other files, which makes it easier for remote att ...

16 december, 2011

CVE-2011-4851

The Control Panel in Parallels Plesk Panel 10.4.4_buil d20111103.1 generates a password form field without disabling the autocomplete feature, which makes it easier for remote attackers to bypass authentication by leveraging an unattended workstation, as ...

16 december, 2011

MS12-004 midiOutPlayNextPolyEvent Heap Overflow Exploit

Target: Microsoft Windows Media
Impact: Code execution

ActFax Server FTP RETR Remote Buffer Overflow Exploit

Target: ActFax Server 4.27 Build 0223 and previous versions
Impact: Arbitrary commands execution

ActFax Server (LPD/LPR) Remote Buffer Overflow Exploit

Target: ActFax Server 4.27 Build 0223 and previous versions
Impact: Arbitrary commands execution