Summary
This host is installed with IBM Global
Console Manager switches and is prone to multiple xss vulnerabilities.
Impact
Successful exploitation will allow attacker
to execute arbitrary HTML and script code in a user's browser session in the context of an affected site.
Impact Level: Application
Solution
Update to firmware version 1.20.20.23447 or newer, For updates refer http://www.ibm.com
Insight
Flaw is due to improper sanitization of
user-supplied input passed via 'query' parameter to kvm.cgi and 'key' parameter to avctalert.php script.
Affected
IBM GCM16 and GCM32 Global Console Manager
switches with firmware before 1.20.20.23447
Detection
Send a crafted request via HTTP GET and
check whether it is able to read cookie or not.
References
Severity
Classification
-
CVE CVE-2014-3080, CVE-2014-3081, CVE-2014-3085 -
CVSS Base Score: 7.1
AV:N/AC:H/Au:S/C:C/I:C/A:C
Related Vulnerabilities