CRLF injection vulnerability in +webvpn+/index.html in WebVPN on Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) allows remote attackers to inject arbitrary HTTP headers as demonstrated by a redirect attack involving a %0d%0aLocation%3a sequence in a URI, or conduct HTTP response splitting attacks via unspecified vectors, aka Bug ID CSCsr09163.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2010-06-29T18:00:00

Updated: 2024-08-07T11:56:14.606Z

Reserved: 2010-06-22T00:00:00

Link: CVE-2008-7257

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2010-06-29T18:30:01.410

Modified: 2018-10-11T20:58:37.070

Link: CVE-2008-7257

cve-icon Redhat

No data.