Eval injection vulnerability in the csco_wrap_js function in /+CSCOL+/cte.js in WebVPN on the Cisco Adaptive Security Appliances (ASA) device with software 8.0(4), 8.1.2, and 8.2.1 allows remote attackers to bypass a DOM wrapper and conduct cross-site scripting (XSS) attacks by setting CSCO_WebVPN['process'] to the name of a crafted function, aka Bug ID CSCsy80694.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T05:04:49.338Z
Reserved: 2009-03-31T00:00:00
Link: CVE-2009-1201
No data.
Status : Deferred
Published: 2009-06-25T17:30:00.203
Modified: 2025-04-09T00:30:58.490
Link: CVE-2009-1201
No data.
OpenCVE Enrichment
No data.
Weaknesses