Director Cross Site Scripting vulnerability

Back to all Security AdvisoriesFollow
Security Advisories ID: 
Published Date: 
September 15, 2011
Advisory Status: 
Advisory Severity: 
CVSS v2 base score 3.3 (AV:A/AC:L/Au:N/C:N/I:P/A:N)
CVE Number: 
No CVEs are associated with this vulnerability.

An attacker can use the HTTP TRACE method to echo malicious script back to the client as part of a Cross Site Scripting (XSS) attack.  No authentication is required.

Affected Products: 

All versions of Director prior to are vulnerable.

Advisory Details: 

Director is vulnerable to reflected (non-persistent) cross site scripting attacks.  User provided data is not validated or sanitized prior to returning it in response to an HTTP TRACE method issued from the client.

The attacker cannot use this vulnerability to steal the administrator's cookies and impersonate the administrator on another machine.  The attacker can use this vulnerability to execute malicious script on the client machine.


Customers can limit the impact of this vulnerability by managing Director only from dedicated machines that do not connect to any other internal or external websites.


Director 5.5 - an interim fix is available in  The fix is available to customers with a valid BlueTouch Online login fromThe fix is available to customers with a valid BlueTouch Online login from

Director 5.4 and earlier - please upgrade to a later release.

Advisory History: 

2015-01-20 Marked as final
2011-09-15 Initial public release