First published: Fri Mar 14 2008(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in securecgi-bin/CSuserCGI.exe in User-Changeable Password (UCP) before 4.2 in Cisco Secure Access Control Server (ACS) for Windows and ACS Solution Engine allow remote attackers to inject arbitrary web script or HTML via an argument located immediately after the Help argument, and possibly unspecified other vectors.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco ACS for Windows | ||
Cisco Secure ACS Solution Engine | ||
Cisco User Changeable Password | =4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-0533 is classified as a medium severity cross-site scripting vulnerability.
To fix CVE-2008-0533, upgrade the Cisco Secure Access Control Server to a version that addresses this vulnerability.
CVE-2008-0533 affects Cisco Secure ACS Solution Engine, Cisco ACS for Windows, and the Cisco User Changeable Password before version 4.2.
Yes, CVE-2008-0533 can be exploited remotely by attackers to inject arbitrary web scripts.
The impact of CVE-2008-0533 includes the potential for attackers to perform unauthorized actions through the execution of injected scripts.