← Back

CVE-2009-1162

nvd nist
Published: Jun 5, 2009Modified: Apr 23, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

Cross-site scripting (XSS) vulnerability in the Spam Quarantine login page in Cisco IronPort AsyncOS before 6.5.2 on Series C, M, and X appliances allows remote attackers to inject arbitrary web script or HTML via the referrer parameter.

Affected (16)

2 products
Ironport Asyncos
Configuration A
16 vulnerable
Vulnerable SoftwareAffected Versions
Cisco
Version 6.0.0-754
Version 6.0.0-757
Version 6.1.0-301
Version 6.1.0-304
Version 6.1.0-306
Version 6.1.0-307
Version 6.1.5-110
Version 6.1.6-003
Version 6.3.5-003
Version 6.3.6-003
Version 6.5.0-405
Version 6.5.1-005
Version 6.6.4.0-273
Cisco
All versions
All versions
All versions

References (12)

Source: psirt@cisco.com
Source: psirt@cisco.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.