Vulnerabilities > CVE-2006-3101 - Cross-Site Scripting vulnerability in Cisco Secure Access Control Server 2.3

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
cisco
exploit available

Summary

Cross-site scripting (XSS) vulnerability in LogonProxy.cgi in Cisco Secure ACS for UNIX 2.3 allows remote attackers to inject arbitrary web script or HTML via the (1) error, (2) SSL, and (3) Ok parameters.

Vulnerable Configurations

Part Description Count
Application
Cisco
1

Exploit-Db

descriptionCisco Secure ACS 2.3 LoginProxy.CGI Cross-Site Scripting Vulnerability. CVE-2006-3101. Remote exploit for unix platform
idEDB-ID:28030
last seen2016-02-03
modified2006-06-15
published2006-06-15
reporterThomas Liam Romanis
sourcehttps://www.exploit-db.com/download/28030/
titleCisco Secure ACS 2.3 LoginProxy.CGI Cross-Site Scripting Vulnerability