CVE-2009-1220

Cisco Adaptive Security Appliance - XSS

Title source: rule

Description

Cross-site scripting (XSS) vulnerability in +webvpn+/index.html in WebVPN on the Cisco Adaptive Security Appliances (ASA) 5520 with software 7.2(4)30 and earlier 7.2 versions including 7.2(2)22, and 8.0(4)28 and earlier 8.0 versions, when clientless mode is enabled, allows remote attackers to inject arbitrary web script or HTML via the Host HTTP header.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Bugs NotHugs · textremotehardware
https://www.exploit-db.com/exploits/32878

Scores

EPSS 0.1973
EPSS Percentile 95.4%

Classification

CWE
CWE-79
Status published

Affected Products (3)

cisco/adaptive_security_appliance
cisco/ios
n/a/n/a

Timeline

Published Apr 01, 2009
Tracked Since Feb 18, 2026