5
CVSSv2

CVE-2009-3457

Published: 29/09/2009 Updated: 10/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Cisco ACE XML Gateway (AXG) and ACE Web Application Firewall (WAF) prior to 6.1 allow remote malicious users to obtain sensitive information via an HTTP request that lacks a handler, as demonstrated by (1) an OPTIONS request or (2) a crafted GET request, leading to a Message-handling Errors message containing a certain client intranet IP address, aka Bug ID CSCtb82159.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco ace web application firewall 6.0\\(2\\)

cisco ace web application firewall 6.0\\(1\\)

cisco ace xml gateway 6.0\\(2\\)

cisco ace xml gateway

cisco ace xml gateway 6.0\\(0\\)

cisco ace xml gateway 6.0\\(1\\)

cisco ace web application firewall

cisco ace web application firewall 6.0\\(0\\)

Exploits

+----------------------------------------------------------------------- -+ | | | ''xxxxxxxxxxxxxxx' | | 'xxxxxxxxxxxxxxxxxxxxxxxxxxx | | 'xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx' | | 'xxxxxxxxxxxxxxxxxxxxxxxxxxxx'''' | | 'xxxxxxxxxxxxxxxxxxxxx'' | | xxxxxxxxxxxxxxxxxx' ' | | 'xxxxxxxxxxxxxxx' ...