Lucene search

K
cveCiscoCVE-2008-0533
HistoryMar 14, 2008 - 8:44 p.m.

CVE-2008-0533

2008-03-1420:44:00
CWE-79
cisco
web.nvd.nist.gov
31
cve-2008-0533
xss
cisco
acs
security vulnerability

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.8

Confidence

High

EPSS

0.013

Percentile

85.7%

Multiple cross-site scripting (XSS) vulnerabilities in securecgi-bin/CSuserCGI.exe in User-Changeable Password (UCP) before 4.2 in Cisco Secure Access Control Server (ACS) for Windows and ACS Solution Engine allow remote attackers to inject arbitrary web script or HTML via an argument located immediately after the Help argument, and possibly unspecified other vectors.

Affected configurations

Nvd
Node
ciscoacs_for_windows
OR
ciscoacs_solution_engine
OR
ciscouser_changeable_passwordMatch4.1
VendorProductVersionCPE
ciscoacs_for_windows*cpe:2.3:a:cisco:acs_for_windows:*:*:*:*:*:*:*:*
ciscoacs_solution_engine*cpe:2.3:a:cisco:acs_solution_engine:*:*:*:*:*:*:*:*
ciscouser_changeable_password4.1cpe:2.3:a:cisco:user_changeable_password:4.1:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.8

Confidence

High

EPSS

0.013

Percentile

85.7%