This application requires Javascript for optimal performance.

Cisco.Secure.ACS.LoginProxy.CGI.XSS

Release Date

Nov 17, 2011

Severity

medium

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Description

This indicates an attack attempt to exploit a Cross Site Scripting vulnerability in Cisco Secure ACS.

The vulnerability is a result of the application's failure to sanitize user supplied input. As a result, a remote attacker can execute arbitrary script code within the context of the application.

Affected Products

Cisco Secure ACS for Unix 2.3 and earlier versions.

Recommended Actions

Refer to the vendor's website for suggested workaround.
http://www.cisco.com/en/US/products/sw/voicesw/ps4625/index.html

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2006-3101

Reference/s

http://www.securityfocus.com/bid/18449 (BugTraq)

Reference: VID-29823