Stack-based buffer overflow in the CSAdmin service in Cisco Secure Access Control Server (ACS) for Windows before 4.1 and ACS Solution Engine before 4.1 allows remote attackers to execute arbitrary code via a crafted HTTP GET request.
https://exchange.xforce.ibmcloud.com/vulnerabilities/31323
http://www.vupen.com/english/advisories/2007/0068
http://www.securityfocus.com/bid/21900
http://www.kb.cert.org/vuls/id/744249
http://www.cisco.com/warp/public/707/cisco-sa-20070105-csacs.shtml