← Vulnerability feed

Vulnerability record · CVE-2006-3101 · published 21 June 2006

CVE-2006-3101: Cisco secure access control server vulnerability

Cisco · Secure Access Control Server

Cross-site scripting (XSS) vulnerability in LogonProxy.cgi in Cisco Secure ACS for UNIX 2.3 allows remote attackers to inject arbitrary web script or HTML via the (1) error, (2) SSL, and (3) Ok parameters.

4.3 CVSS 2.0 Medium EPSS 24% · top 2.2%
4.3CVSS 2.0 base score
24%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
20References, 4 tagged exploit
16 Jun 2026Last modified by NVD

Description

Cross-site scripting (XSS) vulnerability in LogonProxy.cgi in Cisco Secure ACS for UNIX 2.3 allows remote attackers to inject arbitrary web script or HTML via the (1) error, (2) SSL, and (3) Ok parameters.

AV:N/AC:M/Au:N/C:N/I:P/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2006-3101 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2006-4098Cisco secure access control server vulnerabilityStack-based buffer overflow in the CSRadius service in Cisco Secure Access Control Server (ACS) for Windows before 4.1 and ACS Solution Engine before…EPSS 13%10.0CVE-2004-1099Cisco secure access control server vulnerabilityCisco Secure Access Control Server for Windows (ACS Windows) and Cisco Secure Access Control Server Solution Engine (ACS Solution Engine) 3.3.1, when…EPSS 10%10.0CVE-2000-1054Cisco secure access control server vulnerabilityBuffer overflow in CSAdmin module in CiscoSecure ACS Server 2.4(2) and earlier allows remote attackers to cause a denial of service and possibly exec…EPSS 8.4%10.0CVE-2000-1055Cisco secure access control server vulnerabilityBuffer overflow in CiscoSecure ACS Server 2.4(2) and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary comm…EPSS 4.0%9.3CVE-2013-3466Cisco secure access control server improper authentication vulnerabilityThe EAP-FAST authentication module in Cisco Secure Access Control Server (ACS) 4.x before 4.2.1.15.11, when a RADIUS server configuration is enabled,…EPSS 5.1%7.8CVE-2006-4097Cisco secure access control server vulnerabilityMultiple unspecified vulnerabilities in the CSRadius service in Cisco Secure Access Control Server (ACS) for Windows before 4.1 and ACS Solution Engi…EPSS 4.3%7.5CVE-2008-2441Cisco secure acs vulnerabilityCisco Secure ACS 3.x before 3.3(4) Build 12 patch 7, 4.0.x, 4.1.x before 4.1(4) Build 13 Patch 11, and 4.2.x before 4.2(0) Build 124 Patch 4 does not…EPSS 3.0%7.5CVE-2007-0105Cisco secure access control server vulnerabilityStack-based buffer overflow in the CSAdmin service in Cisco Secure Access Control Server (ACS) for Windows before 4.1 and ACS Solution Engine before …EPSS 11%

Source: NIST National Vulnerability Database (record CVE-2006-3101), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.