Topic : | Blue Coat xss
|
SecurityAlert : 4367
CVE : CVE-2008-4485
CWE : CWE-79
SecurityRisk : Low (About)
Remote Exploit : Yes
Local Exploit : No
Victim interaction required : No
Exploit Available : Yes
Credit : jplopezy
Published : 10.10.2008
Affected Software : | Blue Coat |
 Advisory Content :
There is a security issue in the blue coat.
The problem lies in the "Web Filter", which lets you execute an XSS.
This only affects the Internet Explorer browser. "
as a result, could jump the antivirus scan or make spoofing.
POC
http://www.example.com/file.exe?<script>(1)</script>
Juan Pablo Lopez Yacubian
References :
http://www.securitytracker.com/id?1020979
http://www.securityfocus.com/bid/31543
http://www.frsirt.com/english/advisories/2008/2739
http://www.bluecoat.com/support/securityadvisories/icap_patience
http://secunia.com/advisories/32122
http://marc.info/?l=bugtraq&m=122298544725313&w=2
http://marc.info/?l=bugtraq&m=122210321731789&w=2
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
|