Cross-site scripting vulnerability in CiscoSecure ACS 3.0 allows remote attackers to execute arbitrary script or HTML as other web users via the action argument in a link to setup.exe.Referenceshttp://www.iss.net/security_center/static/9353.phphttp://archives.neohapsis.com/archives/bugtraq/2002-06/0156.htmlhttp://online.securityfocus.com/archive/1/278222http://www.securityfocus.com/bid/5026