(:A cross-site scripting vulnerability was reported in the web-based interface of Cisco Identity Services Engine.:A remote attacker could exploit it by enticing their victim into following a specially crafted link in order to execute arbitrary JavaScript or HTML code.::This vulnerability stems from improper validation of user-supplied input of some parameters passed via HTTP GET or POST methods.::Cisco announces that a private exploitation code exists.)