First published: Wed Jun 21 2006(Updated: )
Cross-site scripting (XSS) vulnerability in LogonProxy.cgi in Cisco Secure ACS for UNIX 2.3 allows remote attackers to inject arbitrary web script or HTML via the (1) error, (2) SSL, and (3) Ok parameters.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Secure Access Control Server | =2.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-3101 is considered a medium severity vulnerability due to the potential for cross-site scripting attacks.
To fix CVE-2006-3101, it is recommended to upgrade to a patched version of Cisco Secure ACS for UNIX that resolves the XSS vulnerability.
CVE-2006-3101 affects Cisco Secure Access Control Server version 2.3 for UNIX.
The potential impacts of CVE-2006-3101 include unauthorized access and manipulation of user sessions through the execution of injected scripts.
System administrators and security professionals using Cisco Secure ACS for UNIX are responsible for addressing CVE-2006-3101 by applying security updates.