CVE-2009-0470
Cisco IOS 12.4(23) - XSS
Title source: llmDescription
Multiple cross-site scripting (XSS) vulnerabilities in the HTTP server in Cisco IOS 12.4(23) allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the default URI under (1) level/15/exec/-/ or (2) exec/, a different vulnerability than CVE-2008-3821.
Exploits (1)
Scores
EPSS
0.0542
EPSS Percentile
90.0%
Classification
CWE
CWE-79
Status
published
Affected Products (2)
cisco/ios
n/a/n/a
Timeline
Published
Feb 06, 2009
Tracked Since
Feb 18, 2026