4.3
CVSSv2

CVE-2009-1201

Published: 25/06/2009 Updated: 10/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Eval injection vulnerability in the csco_wrap_js function in /+CSCOL+/cte.js in WebVPN on the Cisco Adaptive Security Appliances (ASA) device with software 8.0(4), 8.1.2, and 8.2.1 allows remote malicious users to bypass a DOM wrapper and conduct cross-site scripting (XSS) attacks by setting CSCO_WebVPN['process'] to the name of a crafted function, aka Bug ID CSCsy80694.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco adaptive_security_appliance 8.2.1

cisco adaptive_security_appliance 8.1.2

cisco adaptive_security_appliance 8.0\\(4\\)

cisco adaptive_security_appliance

Exploits

source: wwwsecurityfocuscom/bid/35476/info Cisco ASA (Adaptive Security Appliance) is prone to a cross-site scripting vulnerability because its Web VPN fails to properly sanitize user-supplied input An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected ...
The Cisco ASA Web VPN versions 80(4), 812, and 821 suffer from cross site scripting, credential theft, and html rewriting bypass vulnerabilities ...