Vulnerabilities > CVE-2002-0938 - Cross-Site Scripting vulnerability in Cisco Secure ACS

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
cisco
exploit available

Summary

Cross-site scripting vulnerability in CiscoSecure ACS 3.0 allows remote attackers to execute arbitrary script or HTML as other web users via the action argument in a link to setup.exe.

Vulnerable Configurations

Part Description Count
Application
Cisco
2

Exploit-Db

descriptionCisco Secure ACS for Windows NT 3.0 .1 Cross-site Scripting Vulnerability. CVE-2002-0938. Remote exploit for windows platform
idEDB-ID:21555
last seen2016-02-02
modified2002-06-14
published2002-06-14
reporterDave Palumbo
sourcehttps://www.exploit-db.com/download/21555/
titleCisco Secure ACS for Windows NT 3.0 - Cross-Site Scripting Vulnerability