Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Cross-site scripting (XSS) vulnerability in +webvpn+/index.html in WebVPN on the Cisco Adaptive Security Appliances (ASA) 5520 with software 7.2(4)30 and earlier 7.2 versions including 7.2(2)22, and 8.0(4)28 and earlier 8.0 versions, when clientless mode is enabled, allows remote attackers to inject arbitrary web script or HTML via the Host HTTP header.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Cisco ASA Appliance WebVPN '+webvpn+/index.html' 跨站脚本攻击漏洞
Vulnerability Description
装载了软件7.2(4)30之前的7.2版本(包括7.2(2)22版本)以及8.0(4)28和之前的8.0版本的Cisco Adaptive Security Appliances (ASA) 5520上的WebVPN中的+webvpn+/index.html存在跨站脚本攻击漏洞。当clientless模式被激活时,远程攻击者可以借助主机HTTP头,注入任意的web脚本或HTML。
CVSS Information
N/A
Vulnerability Type
N/A