《黑客防线》↑在攻与防的对立统一中寻求突破!2001年创刊的黑客技术专业刊物!

设为首页
收藏本站
联系我们
网站导航


技术论坛 - 公共交流区 - 技术交流 - 帖子浏览 - [分享]最新漏洞之八:Cisco BBSM Captive Portal Cross-site Scripting
您是本贴第 42 位浏览者 本版版主
帖子浏览: [分享]最新漏洞之八:Cisco BBSM Captive Portal Cross-site Scripting
  • vippangxievip
  • 等级: 钻石VIP
  • 发贴: 95 贴
  • 货币: 0 金币
  • 积分: 303 分
  • 经验: 3749 点
  • 体力: 16280 点
  • 注册: 2008-03-27
[分享]最新漏洞之八:Cisco BBSM Captive Portal Cross-site Scripting
看了半天还是没明白,还是发出来大家分享吧!!

Vendor: Cisco Systems
Vendor URL: www.cisco.com
Vendor Response: Vendor has been notified and has since addressed the issue in the latest software release.

Description:
     A non-persistent XSS vulnerability is present within the AccessCodeStart.asp page. A
malicious user may leverage this to possibly gain access client information in captive
portal/hotspot locations using this software.

Example:

http://host/ekgnkm/AccessCodeStart.asp?msg=%3Cscript%3Ealert(%22XSS%22);%3C/script%3E

Patch Information:

Patch URL -
http://tools.cisco.com/support/downloads/go/ImageList.x?relVer=5.3&mdfid=278455427&sftType=Building%20Broadband%20Service%20Manager%20(BBSM)%20Updates&optPlat=&nodecount=2&edesignator=null&modelName=Cisco%20Building%20Broadband%20Service%20Manager%205.3&treeMdfId=281527126&treeName=Network%20Monitoring%20and%20Management

Download BBSMPatch5332.zip
爱上破解,有免费的师傅M~~
我很菜!
现在开始自学VB
今年要学会
2008-5-14 9:50:30