Show filters
14 Total Results
Displaying 11-14 of 14
Sort by:
Attacker Value
Unknown
CVE-2002-0938
Disclosure Date: October 04, 2002 (last updated February 22, 2025)
Cross-site scripting vulnerability in CiscoSecure ACS 3.0 allows remote attackers to execute arbitrary script or HTML as other web users via the action argument in a link to setup.exe.
0
Attacker Value
Unknown
CVE-2002-0241
Disclosure Date: May 29, 2002 (last updated February 22, 2025)
NDSAuth.DLL in Cisco Secure Authentication Control Server (ACS) 3.0.1 does not check the Expired or Disabled state of users in the Novell Directory Services (NDS), which could allow those users to authenticate to the server.
0
Attacker Value
Unknown
CVE-2002-0159
Disclosure Date: April 22, 2002 (last updated February 22, 2025)
Format string vulnerability in the administration function in Cisco Secure Access Control Server (ACS) for Windows, 2.6.x and earlier and 3.x through 3.01 (build 40), allows remote attackers to crash the CSADMIN module only (denial of service of administration function) or execute arbitrary code via format strings in the URL to port 2002.
0
Attacker Value
Unknown
CVE-2002-0160
Disclosure Date: April 22, 2002 (last updated February 22, 2025)
The administration function in Cisco Secure Access Control Server (ACS) for Windows, 2.6.x and earlier and 3.x through 3.01 (build 40), allows remote attackers to read HTML, Java class, and image files outside the web root via a ..\.. (modified ..) in the URL to port 2002.
0