CVE-2009-1220
published 2009-04-01CVE-2009-1220: Cross-site scripting (XSS) vulnerability in +webvpn+/index.html in WebVPN on the Cisco Adaptive Security Appliances (ASA) 5520 with software 7.2(4)30 and…
medium4.3CVSS 3.1
AVNACMAuNCNIPAN
EXPLOIT
Cross-site scripting (XSS) vulnerability in +webvpn+/index.html in WebVPN on the Cisco Adaptive Security Appliances (ASA) 5520 with software 7.2(4)30 and earlier 7.2 versions including 7.2(2)22, and 8.0(4)28 and earlier 8.0 versions, when clientless mode is enabled, allows remote attackers to inject arbitrary web script or HTML via the Host HTTP header.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | adaptive_security_appliance | — | — |
| cisco | ios | — | — |
Cisco
Cisco ASA Software WebVPN Cross-Site Scripting Vulnerability
vendor_cisco·2009-04-01·CVSS 4.3
CVE-2009-1220 [MEDIUM] CWE-79 Cisco ASA Software WebVPN Cross-Site Scripting Vulnerability
Cisco ASA Software WebVPN Cross-Site Scripting Vulnerability
Cisco ASA Software versions 8.0.4(28) and prior contain a vulnerability that could allow an unauthenticated, remote attacker to conduct cross-site scripting attacks.
The vulnerability is due to insufficient input validation within the WebVPN clientless mode feature. Attackers could exploit this vulnerability to conduct cross-site scripting attacks, which could result in the execution of arbitrary HTML or scripting code in a user's browser session within the security context of the site.
Proof of concept code is available to demonstrate this cross-site scripting attack.
Cisco has confirmed the vulnerability and released software updates.
To exploit this vulnerability, the clientless mode of the WebVPN feature must be enabled. A
GHSA
GHSA-v3f3-x57x-hfg9: Cross-site scripting (XSS) vulnerability in +webvpn+/index
ghsa_unreviewed·2022-05-02
CVE-2009-1220 [MEDIUM] CWE-79 GHSA-v3f3-x57x-hfg9: Cross-site scripting (XSS) vulnerability in +webvpn+/index
Cross-site scripting (XSS) vulnerability in +webvpn+/index.html in WebVPN on the Cisco Adaptive Security Appliances (ASA) 5520 with software 7.2(4)30 and earlier 7.2 versions including 7.2(2)22, and 8.0(4)28 and earlier 8.0 versions, when clientless mode is enabled, allows remote attackers to inject arbitrary web script or HTML via the Host HTTP header.
Suricata
ET WEB_SPECIFIC_APPS Cisco Adaptive Security Appliance WebVPN Cross Site Scripting Attempt
suricata·2010-07-30
CVE-2009-1220 ET WEB_SPECIFIC_APPS Cisco Adaptive Security Appliance WebVPN Cross Site Scripting Attempt
ET WEB_SPECIFIC_APPS Cisco Adaptive Security Appliance WebVPN Cross Site Scripting Attempt
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS Cisco Adaptive Security Appliance WebVPN Cross Site Scripting Attempt"; flow:established,to_server; http.method; content:"POST"; http.uri; content:"/+webvpn+/index.html"; nocase; pcre:"/(script|img|src|alert|onmouse|onkey|onload|ondragdrop|onblur|onfocus|onclick)/i"; reference:url,www.securityfocus.com/bid/34307/info; reference:url,tools.cisco.com/security/center/viewAlert.x?alertId=17950; reference:cve,2009-1220; classtype:attempted-user; sid:2010505; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, cve CVE_2009_1220, deployment Datacenter, signature_severity Majo
No writeups or analysis indexed.
http://archives.neohapsis.com/archives/fulldisclosure/2009-03/0478.htmlhttp://tools.cisco.com/security/center/viewAlert.x?alertId=17950http://www.securityfocus.com/archive/1/502313/100/0/threadedhttp://www.securityfocus.com/archive/1/502932http://www.securityfocus.com/bid/34307http://www.securitytracker.com/id?1022122http://www.vupen.com/english/advisories/2009/1169https://exchange.xforce.ibmcloud.com/vulnerabilities/49528http://archives.neohapsis.com/archives/fulldisclosure/2009-03/0478.htmlhttp://tools.cisco.com/security/center/viewAlert.x?alertId=17950http://www.securityfocus.com/archive/1/502313/100/0/threadedhttp://www.securityfocus.com/archive/1/502932http://www.securityfocus.com/bid/34307http://www.securitytracker.com/id?1022122http://www.vupen.com/english/advisories/2009/1169https://exchange.xforce.ibmcloud.com/vulnerabilities/49528
2009-04-01
Published