CVE-2009-1201
Cisco Adaptive Security Appliance - Cross-Site Scripting via CSCO_WebVPN Process Function
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-1201. PoCs published by Trustwave's SpiderLabs.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in Cisco ASA Web VPN by injecting malicious JavaScript to steal cookies and display the user's VPN location. The PoC leverages improper input sanitization in the Web VPN interface.
Description
Eval injection vulnerability in the csco_wrap_js function in /+CSCOL+/cte.js in WebVPN on the Cisco Adaptive Security Appliances (ASA) device with software 8.0(4), 8.1.2, and 8.2.1 allows remote attackers to bypass a DOM wrapper and conduct cross-site scripting (XSS) attacks by setting CSCO_WebVPN['process'] to the name of a crafted function, aka Bug ID CSCsy80694.
Exploits (1)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in Cisco ASA Web VPN by injecting malicious JavaScript to steal cookies and display the user's VPN location. The PoC leverages improper input sanitization in the Web VPN interface.