CVE-2009-1220
Cisco Adaptive Security Appliance - XSS
Title source: ruleDescription
Cross-site scripting (XSS) vulnerability in +webvpn+/index.html in WebVPN on the Cisco Adaptive Security Appliances (ASA) 5520 with software 7.2(4)30 and earlier 7.2 versions including 7.2(2)22, and 8.0(4)28 and earlier 8.0 versions, when clientless mode is enabled, allows remote attackers to inject arbitrary web script or HTML via the Host HTTP header.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Bugs NotHugs · textremotehardware
https://www.exploit-db.com/exploits/32878
References (8)
Scores
EPSS
0.1973
EPSS Percentile
95.4%
Classification
CWE
CWE-79
Status
published
Affected Products (3)
cisco/adaptive_security_appliance
cisco/ios
n/a/n/a
Timeline
Published
Apr 01, 2009
Tracked Since
Feb 18, 2026