← back
CVE-2008-0533

CVE-2008-0533

28Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendepss 29%
from disclosure to weapon0 days
Published on NVDMar 14
1st PoCMar 12
exploitation probability
29%top 2% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Multiple cross-site scripting (XSS) vulnerabilities in securecgi-bin/CSuserCGI.exe in User-Changeable Password (UCP) before 4.2 in Cisco Secure Access Control Server (ACS) for Windows and ACS Solution Engine allow remote attackers to inject arbitrary web script or HTML via an argument located immediately after the Help argument, and possibly unspecified other vectors.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.