Show plain JSON{"containers": {"cna": {"affected": [{"product": "n/a", "vendor": "n/a", "versions": [{"status": "affected", "version": "n/a"}]}], "datePublic": "2006-05-15T00:00:00", "descriptions": [{"lang": "en", "value": "Cross-site scripting (XSS) vulnerability in LogonProxy.cgi in Cisco Secure ACS for UNIX 2.3 allows remote attackers to inject arbitrary web script or HTML via the (1) error, (2) SSL, and (3) Ok parameters."}], "problemTypes": [{"descriptions": [{"description": "n/a", "lang": "en", "type": "text"}]}], "providerMetadata": {"dateUpdated": "2018-10-18T14:57:01", "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca", "shortName": "mitre"}, "references": [{"name": "cisco-acs-logonproxy-xss(27166)", "tags": ["vdb-entry", "x_refsource_XF"], "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/27166"}, {"name": "20699", "tags": ["third-party-advisory", "x_refsource_SECUNIA"], "url": "http://secunia.com/advisories/20699"}, {"name": "1016317", "tags": ["vdb-entry", "x_refsource_SECTRACK"], "url": "http://securitytracker.com/id?1016317"}, {"name": "20060617 RE: Cisco Secure ACS Cross Site Scripting Vulnerability.", "tags": ["mailing-list", "x_refsource_BUGTRAQ"], "url": "http://www.securityfocus.com/archive/1/437480/100/0/threaded"}, {"name": "18449", "tags": ["vdb-entry", "x_refsource_BID"], "url": "http://www.securityfocus.com/bid/18449"}, {"name": "20060615 Cisco Secure ACS Cross Site Scripting Vulnerability.", "tags": ["mailing-list", "x_refsource_BUGTRAQ"], "url": "http://www.securityfocus.com/archive/1/437441/100/0/threaded"}, {"name": "26531", "tags": ["vdb-entry", "x_refsource_OSVDB"], "url": "http://www.osvdb.org/26531"}, {"name": "ADV-2006-2384", "tags": ["vdb-entry", "x_refsource_VUPEN"], "url": "http://www.vupen.com/english/advisories/2006/2384"}, {"name": "1116", "tags": ["third-party-advisory", "x_refsource_SREASON"], "url": "http://securityreason.com/securityalert/1116"}, {"name": "20060615 Cisco Secure ACS for UNIX Cross Site Scripting Vulnerability", "tags": ["vendor-advisory", "x_refsource_CISCO"], "url": "http://www.cisco.com/en/US/products/sw/secursw/ps4911/tsd_products_security_response09186a00806b8bdb.html"}], "x_legacyV4Record": {"CVE_data_meta": {"ASSIGNER": "cve@mitre.org", "ID": "CVE-2006-3101", "STATE": "PUBLIC"}, "affects": {"vendor": {"vendor_data": [{"product": {"product_data": [{"product_name": "n/a", "version": {"version_data": [{"version_value": "n/a"}]}}]}, "vendor_name": "n/a"}]}}, "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": {"description_data": [{"lang": "eng", "value": "Cross-site scripting (XSS) vulnerability in LogonProxy.cgi in Cisco Secure ACS for UNIX 2.3 allows remote attackers to inject arbitrary web script or HTML via the (1) error, (2) SSL, and (3) Ok parameters."}]}, "problemtype": {"problemtype_data": [{"description": [{"lang": "eng", "value": "n/a"}]}]}, "references": {"reference_data": [{"name": "cisco-acs-logonproxy-xss(27166)", "refsource": "XF", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/27166"}, {"name": "20699", "refsource": "SECUNIA", "url": "http://secunia.com/advisories/20699"}, {"name": "1016317", "refsource": "SECTRACK", "url": "http://securitytracker.com/id?1016317"}, {"name": "20060617 RE: Cisco Secure ACS Cross Site Scripting Vulnerability.", "refsource": "BUGTRAQ", "url": "http://www.securityfocus.com/archive/1/437480/100/0/threaded"}, {"name": "18449", "refsource": "BID", "url": "http://www.securityfocus.com/bid/18449"}, {"name": "20060615 Cisco Secure ACS Cross Site Scripting Vulnerability.", "refsource": "BUGTRAQ", "url": "http://www.securityfocus.com/archive/1/437441/100/0/threaded"}, {"name": "26531", "refsource": "OSVDB", "url": "http://www.osvdb.org/26531"}, {"name": "ADV-2006-2384", "refsource": "VUPEN", "url": "http://www.vupen.com/english/advisories/2006/2384"}, {"name": "1116", "refsource": "SREASON", "url": "http://securityreason.com/securityalert/1116"}, {"name": "20060615 Cisco Secure ACS for UNIX Cross Site Scripting Vulnerability", "refsource": "CISCO", "url": "http://www.cisco.com/en/US/products/sw/secursw/ps4911/tsd_products_security_response09186a00806b8bdb.html"}]}}}, "adp": [{"providerMetadata": {"orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE", "dateUpdated": "2024-08-07T18:16:05.580Z"}, "title": "CVE Program Container", "references": [{"name": "cisco-acs-logonproxy-xss(27166)", "tags": ["vdb-entry", "x_refsource_XF", "x_transferred"], "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/27166"}, {"name": "20699", "tags": ["third-party-advisory", "x_refsource_SECUNIA", "x_transferred"], "url": "http://secunia.com/advisories/20699"}, {"name": "1016317", "tags": ["vdb-entry", "x_refsource_SECTRACK", "x_transferred"], "url": "http://securitytracker.com/id?1016317"}, {"name": "20060617 RE: Cisco Secure ACS Cross Site Scripting Vulnerability.", "tags": ["mailing-list", "x_refsource_BUGTRAQ", "x_transferred"], "url": "http://www.securityfocus.com/archive/1/437480/100/0/threaded"}, {"name": "18449", "tags": ["vdb-entry", "x_refsource_BID", "x_transferred"], "url": "http://www.securityfocus.com/bid/18449"}, {"name": "20060615 Cisco Secure ACS Cross Site Scripting Vulnerability.", "tags": ["mailing-list", "x_refsource_BUGTRAQ", "x_transferred"], "url": "http://www.securityfocus.com/archive/1/437441/100/0/threaded"}, {"name": "26531", "tags": ["vdb-entry", "x_refsource_OSVDB", "x_transferred"], "url": "http://www.osvdb.org/26531"}, {"name": "ADV-2006-2384", "tags": ["vdb-entry", "x_refsource_VUPEN", "x_transferred"], "url": "http://www.vupen.com/english/advisories/2006/2384"}, {"name": "1116", "tags": ["third-party-advisory", "x_refsource_SREASON", "x_transferred"], "url": "http://securityreason.com/securityalert/1116"}, {"name": "20060615 Cisco Secure ACS for UNIX Cross Site Scripting Vulnerability", "tags": ["vendor-advisory", "x_refsource_CISCO", "x_transferred"], "url": "http://www.cisco.com/en/US/products/sw/secursw/ps4911/tsd_products_security_response09186a00806b8bdb.html"}]}]}, "cveMetadata": {"assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca", "assignerShortName": "mitre", "cveId": "CVE-2006-3101", "datePublished": "2006-06-21T01:00:00", "dateReserved": "2006-06-20T00:00:00", "dateUpdated": "2024-08-07T18:16:05.580Z", "state": "PUBLISHED"}, "dataType": "CVE_RECORD", "dataVersion": "5.1"}