20090331 Cisco ASA5520 Web VPN Host Header XSSmailing list
http://archives.neohapsis.com/archives/fulldisclosure/2009-03/0478.html CVE-2009-1220
Cisco ASA Appliance 7.x/8.0 WebVPN - Cross-Site Scripting
Record summary
CVE-2009-1220 has a selected CVSS score of 4.3; EIP currently links 1 catalogued exploit.
Description
Cross-site scripting (XSS) vulnerability in +webvpn+/index.html in WebVPN on the Cisco Adaptive Security Appliances (ASA) 5520 with software 7.2(4)30 and earlier 7.2 versions including 7.2(2)22, and 8.0(4)28 and earlier 8.0 versions, when clientless mode is enabled, allows remote attackers to inject arbitrary web script or HTML via the Host HTTP header.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBCisco ASA Appliance 7.x/8.0 WebVPN - Cross-Site ScriptingExploitDB exploitby Bugs NotHugsNot analyzed1 file
References
9tools.cisco.comConfirmation
http://tools.cisco.com/security/center/viewAlert.x?alertId=17950 20090331 Cisco ASA5520 Web VPN Host Header XSSmailing list
http://www.securityfocus.com/archive/1/502313/100/0/threaded 20090424 RE: Cisco ASA5520 Web VPN Host Header XSSmailing list
http://www.securityfocus.com/archive/1/502932 34307vdb entry
http://www.securityfocus.com/bid/34307 1022122vdb entry
http://www.securitytracker.com/id?1022122 ADV-2009-1169vdb entry
http://www.vupen.com/english/advisories/2009/1169 asa5520-webvpn-xss(49528)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/49528 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2009-1220