SQL Injection Vulnerability in Cisco Wireless Control System

Related Vulnerabilities: CVE-2010-2826  

Cisco Wireless Control System (WCS) contains a SQL injection vulnerability that could allow an authenticated attacker full access to the vulnerable device, including modification of system configuration; create, modify and delete users; or modify the configuration of wireless devices managed by WCS. Cisco has released software updates that address this vulnerability. There are no workarounds for this vulnerability. This advisory is posted at http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20100811-wcs.