CVE-2009-1202

Cisco Adaptive Security Appliance - XSS

Title source: rule

Description

WebVPN on the Cisco Adaptive Security Appliances (ASA) device with software 8.0(4), 8.1.2, and 8.2.1 allows remote attackers to bypass certain protection mechanisms involving URL rewriting and HTML rewriting, and conduct cross-site scripting (XSS) attacks, by modifying the first hex-encoded character in a /+CSCO+ URI, aka Bug ID CSCsy80705.

Scores

EPSS 0.0032
EPSS Percentile 54.3%

Classification

CWE
CWE-79
Status published

Affected Products (5)

cisco/adaptive_security_appliance
cisco/adaptive_security_appliance
cisco/adaptive_security_appliance
cisco/adaptive_security_appliance
n/a/n/a

Timeline

Published Jun 25, 2009
Tracked Since Feb 18, 2026