The vulnerability is due to insufficient input validation of the HTTP host tag parameter. An attacker could exploit this vulnerability by convincing a user to click a specific link.
Additional information about XSS attacks and potential mitigations is at the following links:
Understanding Cross-Site Scripting Threat Vectors
Cross-Site Scripting
Cisco has not released software updates that address this vulnerability. Workarounds that address this vulnerability are not available.
This advisory is available at the following link: http://ift.tt/1TEi5jt
from Cisco Security Advisory http://ift.tt/1TEi5jt
No comments:
Post a Comment
Note: Only a member of this blog may post a comment.