Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2009-1220

Опубликовано: 01 апр. 2009
Источник: nvd
CVSS2: 4.3
EPSS Средний

Описание

Cross-site scripting (XSS) vulnerability in +webvpn+/index.html in WebVPN on the Cisco Adaptive Security Appliances (ASA) 5520 with software 7.2(4)30 and earlier 7.2 versions including 7.2(2)22, and 8.0(4)28 and earlier 8.0 versions, when clientless mode is enabled, allows remote attackers to inject arbitrary web script or HTML via the Host HTTP header.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:h:cisco:adaptive_security_appliance:5520:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios:7.2\(2\)22:*:*:*:*:*:*:*

EPSS

Процентиль: 95%
0.19731
Средний

4.3 Medium

CVSS2

Дефекты

CWE-79

Связанные уязвимости

github
почти 4 года назад

Cross-site scripting (XSS) vulnerability in +webvpn+/index.html in WebVPN on the Cisco Adaptive Security Appliances (ASA) 5520 with software 7.2(4)30 and earlier 7.2 versions including 7.2(2)22, and 8.0(4)28 and earlier 8.0 versions, when clientless mode is enabled, allows remote attackers to inject arbitrary web script or HTML via the Host HTTP header.

EPSS

Процентиль: 95%
0.19731
Средний

4.3 Medium

CVSS2

Дефекты

CWE-79