CVE-2009-1162 describes a cross-site scripting (XSS) vulnerability in the Spam Quarantine login page of Cisco IronPort AsyncOS versions prior to 6.5.2 on Series C, M, and X appliances, allowing remote attackers to inject malicious web script or HTML via the referrer parameter. This vulnerability has a CVSS score of 4.3 (Medium), indicating a network-based attack with medium complexity and a potential impact of partial integrity compromise. There is no evidence of active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.0.0-754CPE matchmatch criteria | cpe:2.3:o:cisco:ironport_asyncos:6.0.0-754:*:*:*:*:*:*:* | ||
6.0.0-757CPE matchmatch criteria | cpe:2.3:o:cisco:ironport_asyncos:6.0.0-757:*:*:*:*:*:*:* | ||
6.1.0-301CPE matchmatch criteria | cpe:2.3:o:cisco:ironport_asyncos:6.1.0-301:*:*:*:*:*:*:* | ||
6.1.0-304CPE matchmatch criteria | cpe:2.3:o:cisco:ironport_asyncos:6.1.0-304:*:*:*:*:*:*:* | ||
6.1.0-306CPE matchmatch criteria | cpe:2.3:o:cisco:ironport_asyncos:6.1.0-306:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:P/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.