CVE-2009-1201: XSS
Eval injection vulnerability in the cscowrapjs function in /+CSCOL+/cte.js in WebVPN on the Cisco Adaptive Security Appliances (ASA) device with software 8.0(4), 8.1.2, and 8.2.1 allows remote attackers to bypass a DOM wrapper and conduct cross-site scripting (XSS) attacks by setting CSCOWebVPN['process'] to the name of a crafted function, aka Bug ID CSCsy80694.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-1201?
CVE-2009-1201 has been classified with a medium severity rating due to its potential for cross-site scripting attacks.
How do I fix CVE-2009-1201?
To mitigate CVE-2009-1201, update the Cisco Adaptive Security Appliance software to a version that is not susceptible to this vulnerability.
What systems are affected by CVE-2009-1201?
CVE-2009-1201 affects Cisco Adaptive Security Appliances running software versions 8.0(4), 8.1.2, and 8.2.1.
What is the impact of CVE-2009-1201?
The impact of CVE-2009-1201 includes the potential for remote attackers to execute cross-site scripting attacks.
Can CVE-2009-1201 be exploited remotely?
Yes, CVE-2009-1201 can be exploited remotely, allowing attackers to bypass security mechanisms.