CVE-2014-2120 | Cisco ASA up to 8.4.7/9.1.4 WebVPN Login Page /+CSCOE+/logon.html cross site scripting (CSCun19025 / Nessus ID 213167)
A vulnerability was found in Cisco ASA up to 8.4.7/9.1.4 and classified as problematic. Affected by this issue is some unknown functionality of the file /+CSCOE+/logon.html of the component WebVPN Login Page. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2014-2120. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.