vendor:
Cisco Collaboration Server 5
by:
s4squatch of SecureState R&D Team
7,5
CVSS
HIGH
Cross-Site Scripting (XSS) and Source Code Disclosure
79 (XSS) and 522 (Source Code Disclosure)
CWE
Product Name: Cisco Collaboration Server 5
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008
Cisco Collaboration Server 5 XSS, Source Code Disclosure
Cisco Collaboration Server 5 is vulnerable to Cross-Site Scripting (XSS) and Source Code Disclosure. An attacker can inject malicious JavaScript code into the vulnerable parameter of the LoginPage.jhtml file. Additionally, the source code of .jhtml files can be revealed to the end user by requesting any of the following: Normal File, Modified 1, Modified 2, Modified 3, and Modified 4.
Mitigation:
Ensure that user input is properly sanitized and filtered before being used in the application. Additionally, ensure that the source code of .jhtml files is not revealed to the end user.