CVE-2009-1201
Cisco Adaptive Security Appliance - XSS
Title source: ruleDescription
Eval injection vulnerability in the csco_wrap_js function in /+CSCOL+/cte.js in WebVPN on the Cisco Adaptive Security Appliances (ASA) device with software 8.0(4), 8.1.2, and 8.2.1 allows remote attackers to bypass a DOM wrapper and conduct cross-site scripting (XSS) attacks by setting CSCO_WebVPN['process'] to the name of a crafted function, aka Bug ID CSCsy80694.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Trustwave's SpiderLabs · htmlremotehardware
https://www.exploit-db.com/exploits/33055
References (6)
Scores
EPSS
0.0486
EPSS Percentile
89.4%
Classification
CWE
CWE-79
Status
published
Affected Products (5)
cisco/adaptive_security_appliance
cisco/adaptive_security_appliance
cisco/adaptive_security_appliance
cisco/adaptive_security_appliance
n/a/n/a
Timeline
Published
Jun 25, 2009
Tracked Since
Feb 18, 2026