Check Point Reference: | CPAI-2009-067 |
Date Published: | 14 Apr 2009 |
Severity: | Medium |
Last Updated: | Thursday 01 January, 2009 |
Source: | Bugtraq ID: 34307 |
Industry Reference: | CVE-2009-1220 |
Protection Provided by: | |
Who is Vulnerable? | Cisco, ASA 5520 Cisco, IOS 7.2(2)22 |
Vulnerability Description | Cisco ASA is vulnerable to cross-site scripting vulnerability. The vulnerability is caused by improper validation of user-supplied input by the index.html page. An attacker may leverage this issue via the Host HTTP header to execute script in a victim's Web browser and steal cookie-based authentication credentials. |
Update/Patch Avaliable | No solution available as of April 13, 2009. |
Vulnerability Details | An attacker can exploit this issue by enticing an unsuspecting victim to follow a malicious HTTP request. |