1 results (0.002 seconds)
CVSS: 6.8EPSS: 1%CPEs: 5EXPL: 0
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2009-2631
https://notcve.org/view.php?id=CVE-2009-2631
04 Dec 2009 — Multiple clientless SSL VPN products that run in web browsers, including Stonesoft StoneGate; Cisco ASA; SonicWALL E-Class SSL VPN and SonicWALL SSL VPN; SafeNet SecureWire Access Gateway; Juniper Networks Secure Access; Nortel CallPilot; Citrix Access Gateway; and other products, when running in configurations that do not restrict access to the same domain as the VPN, retrieve the content of remote URLs from one domain and rewrite them so they originate from the VPN's domain, which violates the same origin... • http://kb.juniper.net/KB15799 • CWE-264: Permissions, Privileges, and Access Controls •