You are here: silicon.com > Software > Security Strategy

Security Strategy

Security flaw threatens Cisco website

Oops...

By CNET Networks

Published: 20 December 2002 12:40 GMT

By Patrick Gray

A cross-site scripting (XSS) vulnerability has been discovered in the cisco.com website.

Securiteam.com, an online security portal, issued an advisory which said: "The vulnerability would allow attackers to cause users to view third-party malicious JavaScript or HTML code as if it were the legitimate content offered by Cisco."

XSS vulnerabilities are at their most serious when user log-ins are involved. They may in some circumstances make it possible for an attacker to "steal" a user's session information, potentially allowing them to login as the victim user.

It is not known if Cisco, which does have a client log-in function on its website, is vulnerable to this extent. "Session theft" attack types are not very easy to carry out, and must be directed at the user of the affected site, not the site itself.

The Cisco website log-in function allows users to "...place and manage orders for Cisco networking products and services via the internet", the advisory said.

Logged-in customers can also download versions of Cisco's IOS software not normally available to the public.

XSS vulnerabilities have come into fashion lately, with many security researchers focusing their efforts in detection and elimination of the security problem.

The recently held hacking competition, OpenHack IV, dished out $500 (£320) to a single entrant, Jeremy Poteet, who found XSS vulnerabilities in the application being tested, which was engineered by Oracle.

Cisco was not immediately available for comment.

Patrick Gray writes for ZDNet Australia

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Steve Ranger Editor's Blog: Is software's future now behind it? The industry is short on big ideas - at least for now

Tim Ferguson Is Salesforce.com sitting pretty for cloud wars? Comment: Software giants face a well prepared foe


  • Jobs
SEO Programming Manager

Strong software analytical skills (MS Excel) Extremely detail & results-oriented Excellent organisational skills Strong communication skills with the ...

ASP.Net Web Developer CHANCE TO SHINE!

To upload a copy of your CV to our team of specialist contract & permanent recruiters in Dublin please use the 'apply now' function or visit our ...

Unix System Administrator, 30k - 40k, Dublin

To upload a copy of your CV to our team of specialist contract & permanent recruiters in Dublin please use the 'apply now' function or visit our ...

Agenda Setters 2008
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: