cbcvebase.
CVE-2008-0533
published 2008-03-14

CVE-2008-0533: Multiple cross-site scripting (XSS) vulnerabilities in securecgi-bin/CSuserCGI.exe in User-Changeable Password (UCP) before 4.2 in Cisco Secure Access Control…

medium4.3CVSS 3.1
AVNACMAuNCNIPAN
EXPLOIT
Multiple cross-site scripting (XSS) vulnerabilities in securecgi-bin/CSuserCGI.exe in User-Changeable Password (UCP) before 4.2 in Cisco Secure Access Control Server (ACS) for Windows and ACS Solution Engine allow remote attackers to inject arbitrary web script or HTML via an argument located immediately after the Help argument, and possibly unspecified other vectors.

Affected

2 ranges
VendorProductVersion rangeFixed in
ciscosecure
ciscouser_changeable_password