Aerosol Posted February 25, 2015 Report Posted February 25, 2015 Cisco Ironport AsyncOS Cross Site ScriptingVendor: CiscoProduct webpage: http://www.cisco.comAffected version(s): Cisco Ironport ESA - AsyncOS 8.0.1-023 Cisco Ironport WSA - AsyncOS 8.5.5-022 Cisco Ironport SMA - AsyncOS 8.4.0-126Date: 24/02/2015Credits: Glafkos CharalambousCVE: CVE-2013-6780Disclosure Timeline:28-10-2014: Vendor Notification28-10-2014: Vendor Response/Feedback22-01-2015: Vendor Fix/Patch24-02-2015: Public DisclosureDescription:Cisco AsyncOS is vulnerable to unauthenticated Cross-site scripting (XSS), caused by improper validationof user supplied input in the (uploader.swf) Uploader component in Yahoo! versions 2.5.0 through 2.9.0.An attacker is able to inject arbitrary web script or HTML via the allowedDomain parameter.XSS Payload:http(s)://domain.com/yui/uploader/assets/uploader.swf?allowedDomain=\"})))}catch(e){alert('XSS');}//References:https://tools.cisco.com/bugsearch/bug/CSCur44409https://tools.cisco.com/bugsearch/bug/CSCur89626https://tools.cisco.com/bugsearch/bug/CSCur89624http://yuilibrary.com/support/20131111-vulnerability/http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-6780https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6780-----BEGIN PGP SIGNATURE-----Version: GnuPG v2.0.22 (MingW32) mQENBFE6TCMBCADQKVLT3xkJDQpUE6M3akJdFRWgFEy2pwoDbnOGDhw6yQYObDEuUlixRV5uxaIwzh9xPSS36B72bhQC3isHuqDu3xVhx9OX7XlLheXDZJdRbNIXQ3YPk1uYQizuoIpHq08xEq4V2CXq7ovZPhWI6+iJt6QkVYvZXJdyoTKT8bLaFSOEfLeyAgkCQdXOgnzmNWeedxp0xGAjKL7qIhLETp/MK46ndo5hF8RIbVs59gWdu4GxXr96qViJLiAYO1dQNLc+LShMnue91neTjLoeJkpgqLfEGKV459eCJNqxlylIVbxyTmigExftZKAdNFHat0txK0fB/bLOwRnNFqYWQxanABEBAAG0KEdsYWZrb3MgQ2hhcmFsYW1ib3VzIDxnbGFma29zQGdtYWlsLmNvbT6JATgEEwECACIFAlE6TCMCGw8GCwkIBwMCBhUIAgkKCwQWAgMBAh4BAheAAAoJEHAhLSD814yOAcoIALO6d2AQM0l9KD9hPIody4VYOgY8stBrumI+t8njzJOYCCLdzB781vCAa0vINPFuFxGp2e8EfMfvf8+ZS6kC8EOQ6XyC8eq6imc1Q+tFMwTgykJZPFdosfXjBwg9jos/CR4dI6RZuzGC/FdXjpTAypbEn3m2a+DBb6CUPeB9nVQq6ukRGbuZ8S+veWRNFwKkTSwC0HKtf9Od+JBrLKesNa3LWLo8q7+dV3VS8rf8cmOOGBuaITzj87iRpgAgkF3MATa1Vb2nbbdYMpvHbzoj62mSqRiyEp1SOY9XkgcL2ORsjgjww7GpH3F8LFvaHSHVz+037+E/+i/OSTS7o6gY4eI==yiro-----END PGP SIGNATURE-----Source Quote