<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Advisory: Cross Site Scripting in CiscoWorks</title>
	<atom:link href="http://www.liquidmatrix.org/blog/2007/12/05/advisory-cross-site-scripting-in-ciscoworks/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.liquidmatrix.org/blog/2007/12/05/advisory-cross-site-scripting-in-ciscoworks/</link>
	<description>Bringing Fire To The Village: Your Source For Computer, Network &#38; Information Security News from Dave Lewis, Security Blogger</description>
	<pubDate>Sat, 11 Oct 2008 10:50:41 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.2</generator>
		<item>
		<title>By: KATIRINA TRACY</title>
		<link>http://www.liquidmatrix.org/blog/2007/12/05/advisory-cross-site-scripting-in-ciscoworks/#comment-68055</link>
		<dc:creator>KATIRINA TRACY</dc:creator>
		<pubDate>Mon, 18 Feb 2008 21:20:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.liquidmatrix.org/blog/2007/12/05/advisory-cross-site-scripting-in-ciscoworks/#comment-68055</guid>
		<description>Guys....I need someone to train my client on a 1/2 day session on CiscoWorks LMS.  The gig is up here in Northern New Jersey.   Great way to make $1500 during a day off.  Let me know if u know anyone or if you are interested.  THX!!!!!   Kat
201-505-9489</description>
		<content:encoded><![CDATA[<p>Guys&#8230;.I need someone to train my client on a 1/2 day session on CiscoWorks LMS.  The gig is up here in Northern New Jersey.   Great way to make $1500 during a day off.  Let me know if u know anyone or if you are interested.  THX!!!!!   Kat<br />
201-505-9489</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: בניית אתרים</title>
		<link>http://www.liquidmatrix.org/blog/2007/12/05/advisory-cross-site-scripting-in-ciscoworks/#comment-67982</link>
		<dc:creator>בניית אתרים</dc:creator>
		<pubDate>Fri, 01 Feb 2008 12:38:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.liquidmatrix.org/blog/2007/12/05/advisory-cross-site-scripting-in-ciscoworks/#comment-67982</guid>
		<description>i looked for this article couple of months
thanks a lot</description>
		<content:encoded><![CDATA[<p>i looked for this article couple of months<br />
thanks a lot</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dave Lewis</title>
		<link>http://www.liquidmatrix.org/blog/2007/12/05/advisory-cross-site-scripting-in-ciscoworks/#comment-67859</link>
		<dc:creator>Dave Lewis</dc:creator>
		<pubDate>Fri, 04 Jan 2008 15:02:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.liquidmatrix.org/blog/2007/12/05/advisory-cross-site-scripting-in-ciscoworks/#comment-67859</guid>
		<description>@Albert

Thanks. Yes, this would require a Ciscoworks user to follow a specially crafted link that would be used to capture the aforementioned information. Beyond that I'm reticent to provide more information. I would suggest that you apply the patch that fixes this issue if that is an option.</description>
		<content:encoded><![CDATA[<p>@Albert</p>
<p>Thanks. Yes, this would require a Ciscoworks user to follow a specially crafted link that would be used to capture the aforementioned information. Beyond that I&#8217;m reticent to provide more information. I would suggest that you apply the patch that fixes this issue if that is an option.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Albert Yu</title>
		<link>http://www.liquidmatrix.org/blog/2007/12/05/advisory-cross-site-scripting-in-ciscoworks/#comment-67858</link>
		<dc:creator>Albert Yu</dc:creator>
		<pubDate>Fri, 04 Jan 2008 14:52:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.liquidmatrix.org/blog/2007/12/05/advisory-cross-site-scripting-in-ciscoworks/#comment-67858</guid>
		<description>Dave,

Thanks for your contribution.  Our company is also using Ciscoworks on windows platform so we would like to understand more about this possible XSS attack - Cross Site Scripting in CiscoWorks.   If I understand correctly, the hackers will be able to obtain the cookies and username/passwords for the ciscoworks application without knowing any proper credential.  The cross site script can be executed without any authentictaion required due to the vulnerability.   

Thanks for your clarification.</description>
		<content:encoded><![CDATA[<p>Dave,</p>
<p>Thanks for your contribution.  Our company is also using Ciscoworks on windows platform so we would like to understand more about this possible XSS attack - Cross Site Scripting in CiscoWorks.   If I understand correctly, the hackers will be able to obtain the cookies and username/passwords for the ciscoworks application without knowing any proper credential.  The cross site script can be executed without any authentictaion required due to the vulnerability.   </p>
<p>Thanks for your clarification.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
