Back to search
CVE-2008-7257
Published: Jun 29, 2010
Modified: Aug 7, 2024
PUBLISHED
Description
CRLF injection vulnerability in +webvpn+/index.html in WebVPN on Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) allows remote attackers to inject arbitrary HTTP headers as demonstrated by a redirect attack involving a %0d%0aLocation%3a sequence in a URI, or conduct HTTP response splitting attacks via unspecified vectors, aka Bug ID CSCsr09163.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
41159
vdb-entry
x_refsource_BID
20100624 [SWRX-2010-001] Cisco ASA HTTP Response Splitting Vulnerability
mailing-list
x_refsource_BUGTRAQ
1024155
vdb-entry
x_refsource_SECTRACK
cisco-asa-interface-response-splitting(59850)
vdb-entry
x_refsource_XF
http://www.secureworks.com/ctu/advisories/SWRX-2010-001
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now