4.3
CVSSv2

CVE-2009-1202

Published: 25/06/2009 Updated: 10/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

WebVPN on the Cisco Adaptive Security Appliances (ASA) device with software 8.0(4), 8.1.2, and 8.2.1 allows remote malicious users to bypass certain protection mechanisms involving URL rewriting and HTML rewriting, and conduct cross-site scripting (XSS) attacks, by modifying the first hex-encoded character in a /+CSCO+ URI, aka Bug ID CSCsy80705.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco adaptive_security_appliance 8.2.1

cisco adaptive_security_appliance 8.1.2

cisco adaptive_security_appliance 8.0\\(4\\)

cisco adaptive_security_appliance

Exploits

The Cisco ASA Web VPN versions 80(4), 812, and 821 suffer from cross site scripting, credential theft, and html rewriting bypass vulnerabilities ...