Multiple buffer overflows in the authentication functionality in the web-server module in Cisco CiscoWorks Common Services before 4.0 allow remote attackers to execute arbitrary code via a session on TCP port (1) 443 or (2) 1741, aka Bug ID CSCti41352.
http://www.vupen.com/english/advisories/2010/2793
http://www.securityfocus.com/bid/44468
http://www.cisco.com/en/US/products/products_security_advisory09186a0080b51501.shtml
http://securitytracker.com/id?1024646