Release date:
Updated on: 2013-06-27
Affected Systems:
Cisco Content Security Management
Description:
--------------------------------------------------------------------------------
CVE (CAN) ID: CVE-2013-3396
Cisco Content Security Management is a unified solution for email and Web Security Management.
The Cisco Content Security Management Web framework has a Security vulnerability that allows unauthenticated remote attackers to perform XSS attacks on the Web interface users of the affected system. This vulnerability is caused by insufficient parameter input verification. Attackers exploit this vulnerability by enticing users to access malicious links.
<* Source: vendor
Link: http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-3396
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Cisco
-----
Cisco has released a Security Bulletin (CVE-2013-3396) and patches for this:
CVE-2013-3396: Cisco Content Security Management Cross-Site Scripting Vulnerability
Link: http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-3396