CVE-2008-0533
Multiple cross-site scripting (XSS) vulnerabilities in securecgi-bin/CSuserCGI.exe in User-Changeable Password (UCP) before 4.2 in Cisco Secure Access Control Server (ACS) for Windows and ACS Solution Engine allow remote attackers to inject arbitrary…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 28.8%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
Multiple cross-site scripting (XSS) vulnerabilities in securecgi-bin/CSuserCGI.exe in User-Changeable Password (UCP) before 4.2 in Cisco Secure Access Control Server (ACS) for Windows and ACS Solution Engine allow remote attackers to inject arbitrary web script or HTML via an argument located immediately after the Help argument, and possibly unspecified other vectors.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 28.79% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- cisco/acs for windows · cisco/acs solution engine · cisco/user changeable password
- Source
- psirt@cisco.com
References
- http://secunia.com/advisories/29351Patch, Vendor Advisory
- http://securityreason.com/securityalert/3743
- http://securitytracker.com/id?1019607
- http://www.cisco.com/en/US/products/products_security_advisory09186a008095f0c4.shtmlPatch
- http://www.recurity-labs.com/content/pub/RecurityLabs_Cisco_ACS_UCP_advisory.txt
- http://www.securityfocus.com/archive/1/489463/100/0/threaded
- http://www.securityfocus.com/bid/28222Exploit
- http://www.vupen.com/english/advisories/2008/0868
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41156
- http://secunia.com/advisories/29351Patch, Vendor Advisory
- http://securityreason.com/securityalert/3743
- http://securitytracker.com/id?1019607
- http://www.cisco.com/en/US/products/products_security_advisory09186a008095f0c4.shtmlPatch
- http://www.recurity-labs.com/content/pub/RecurityLabs_Cisco_ACS_UCP_advisory.txt
- http://www.securityfocus.com/archive/1/489463/100/0/threaded
- http://www.securityfocus.com/bid/28222Exploit
- http://www.vupen.com/english/advisories/2008/0868
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41156
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.