How to Buy
This script is (C) 2012-2014 Tenable Network Security, Inc.
The remote device is missing a vendor-supplied security patch.
On June 19, 2009, Cisco released a security response for cross-site
scripting and cross-site request forgery vulnerabilities in the HTTP
server in IOS.
Exploitation of these vulnerabilities could result in attacker
remote attacker could trick a user into making a maliciously crafted
This plugin checks if the appropriate fix for the advisory has been
See also :
Apply the relevant patch referenced in the Cisco Security Advisory
Risk factor :
Medium / CVSS Base Score : 4.3
CVSS Temporal Score : 3.6
Public Exploit Available : true
Nessus Plugin ID: 17795 ()
Bugtraq ID: 33260
CVE ID: CVE-2008-3821CVE-2009-0470
Upgrade to Nessus Professional today!
Start your free Nessus Cloud trial now!
Begin Free Trial
The cookie settings on this website are set to 'allow all cookies' to give you the very best website experience. If you continue without changing these settings, you consent to this - but if you want, you can opt out of all cookies by clicking below.