CVE-2009-1220
CVE-2009-1220
Cross-site scripting (XSS) vulnerability in +webvpn+/index.html in WebVPN on the Cisco Adaptive Security Appliances (ASA) 5520 with software 7.2(4)30 and earlier 7.2 versions including 7.2(2)22, and 8.0(4)28 and earlier 8.0 versions, when clientless mode is enabled, allows remote attackers to inject arbitrary web script or HTML via the Host HTTP header.
Produtos afetados
n/a · n/aPoCs públicas encontradas — 1
exploitdbwww.exploit-db.com/exploits/32878não verificado⚠ Recursos públicos, para você avaliar a exposição de sistemas que controla ou está autorizado a testar. Teste apenas com autorização.
Quer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
http://archives.neohapsis.com/archives/fulldisclosure/2009-03/0478.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/49528http://tools.cisco.com/security/center/viewAlert.x?alertId=17950http://www.securityfocus.com/archive/1/502313/100/0/threadedhttp://www.securityfocus.com/archive/1/502932http://www.securityfocus.com/bid/34307http://www.securitytracker.com/id?1022122http://www.vupen.com/english/advisories/2009/1169