漏洞信息详情
Cisco Small Business 220 Series Smart Plus Switches 跨站脚本漏洞
漏洞简介
Cisco Small Business 220 Series Smart Plus Switches是美国思科(Cisco)公司的220系列可堆叠管理型交换机产品。
Cisco Small Business 220 Series Smart Plus Switches中的web-based管理界面存在跨站脚本漏洞。远程攻击者可借助特制的URL利用该漏洞注入任意Web脚本或HTML。以下版本受到影响:运行1.0.0.17,1.0.0.18,1.0.0.19版本固件的Cisco Small Business 220 Series Smart Plus Switches。
漏洞公告
目前厂商已经发布了升级补丁以修复此安全问题,补丁获取链接:
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160831-sps1
参考网址
来源:CISCO
链接:http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160831-sps1
来源:BID
链接:http://www.securityfocus.com/bid/92713 来源:NSFOCUS 名称:34709 链接:http://www.nsfocus.net/vulndb/34709
受影响实体
- Cisco Small_business_220_series_smart_plus_switches:1.0.0.19<!--2000-1-1-->
- Cisco Small_business_220_series_smart_plus_switches:1.0.0.17<!--2000-1-1-->
- Cisco Small_business_220_series_smart_plus_switches:1.0.0.18<!--2000-1-1-->
补丁
- Cisco Small Business 220 Series Smart Plus Switches 跨站脚本漏洞的修复措施<!--2016-9-1-->
还没有评论,来说两句吧...