CVE-2010-0440
published 2010-02-03CVE-2010-0440: Cross-site scripting (XSS) vulnerability in +CSCOT+/translation in Cisco Secure Desktop 3.4.2048, and other versions before 3.5; as used in Cisco ASA appliance…
PriorityP423medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EXPLOIT
EPSS
4.36%
90.2th percentile
Cross-site scripting (XSS) vulnerability in +CSCOT+/translation in Cisco Secure Desktop 3.4.2048, and other versions before 3.5; as used in Cisco ASA appliance before 8.2(1), 8.1(2.7), and 8.0(5); allows remote attackers to inject arbitrary web script or HTML via a crafted POST parameter, which is not properly handled by an eval statement in binary/mainv.js that writes to start.html.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | adaptive_security_appliance_software | >= 8.0 < 8.0\(5\) | 8.0\(5\) |
| cisco | adaptive_security_appliance_software | >= 8.1 < 8.1\(2.7\) | 8.1\(2.7\) |
| cisco | adaptive_security_appliance_software | >= 8.2 < 8.2\(1\) | 8.2\(1\) |
| cisco | secure_desktop | < 3.5 | 3.5 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_cisco4.3MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Cisco Secure Desktop up to 3.1.1.26 POST cross site scripting (Alert 19843 / EDB-33567)
vuldb·2026-04-30·CVSS 4.3
CVE-2010-0440 [MEDIUM] Cisco Secure Desktop up to 3.1.1.26 POST cross site scripting (Alert 19843 / EDB-33567)
A vulnerability described as problematic has been identified in Cisco Secure Desktop up to 3.1.1.26. The affected element is an unknown function. Such manipulation of the argument POST leads to cross site scripting.
This vulnerability is listed as CVE-2010-0440. The attack may be performed from remote. In addition, an exploit is available.
Upgrading the affected component is recommended.
GHSA
GHSA-v9jr-23rj-wr7x: Cross-site scripting (XSS) vulnerability in +CSCOT+/translation in Cisco Secure Desktop 3
ghsa_unreviewed·2022-05-02
CVE-2010-0440 [MEDIUM] CWE-79 GHSA-v9jr-23rj-wr7x: Cross-site scripting (XSS) vulnerability in +CSCOT+/translation in Cisco Secure Desktop 3
Cross-site scripting (XSS) vulnerability in +CSCOT+/translation in Cisco Secure Desktop 3.4.2048, and other versions before 3.5; as used in Cisco ASA appliance before 8.2(1), 8.1(2.7), and 8.0(5); allows remote attackers to inject arbitrary web script or HTML via a crafted POST parameter, which is not properly handled by an eval statement in binary/mainv.js that writes to start.html.
Cisco
Cisco Secure Desktop Remote Cross-Site Scripting Vulnerability
vendor_cisco·2010-02-01·CVSS 4.3
CVE-2010-0440 [MEDIUM] CWE-79 Cisco Secure Desktop Remote Cross-Site Scripting Vulnerability
Cisco Secure Desktop Remote Cross-Site Scripting Vulnerability
Cisco Secure Desktop contains a vulnerability that could allow an unauthenticated, remote attacker to conduct cross-site scripting attacks.
The vulnerability is due to a lack of input sanitation in the Cisco Secure Desktop. An unauthenticated, remote attacker could exploit this vulnerability by convincing a targeted user to visit a malicious website that is designed to submit an HTTP POST request to the web interface of the affected product. If the targeted user visits the malicious page, the attacker could execute arbitrary script code in the browser of the user in the security context of the affected site.
Proof-of-concept code is publicly available.
Cisco has confirmed this vulnerability and released updated software.
To
No detection rules found.
No writeups or analysis indexed.
http://secunia.com/advisories/38397http://tools.cisco.com/security/center/viewAlert.x?alertId=19843http://www.coresecurity.com/content/cisco-secure-desktop-xsshttp://www.securityfocus.com/archive/1/509290/100/0/threadedhttp://www.securityfocus.com/bid/37960http://www.vupen.com/english/advisories/2010/0273http://secunia.com/advisories/38397http://tools.cisco.com/security/center/viewAlert.x?alertId=19843http://www.coresecurity.com/content/cisco-secure-desktop-xsshttp://www.securityfocus.com/archive/1/509290/100/0/threadedhttp://www.securityfocus.com/bid/37960http://www.vupen.com/english/advisories/2010/0273
2010-02-03
Published