Description
|
|
A vulnerability has been identified in Cisco Guard, which could be exploited by attackers to execute arbitrary scripting code. This flaw is due to an input validation error in the anti-spoofing feature that does not properly validate inspected HTTP traffic before being sent to the browser via a "meta-refresh" tag, which could be exploited by attackers to execute arbitrary scripting code by tricking a user into following a specially crafted URL.
Note : This issue is exploitable when Cisco Guard is running active basic protection, going through basic/redirect protection.
|