2.6
CVSSv2

CVE-2006-3289

Published: 28/06/2006 Updated: 20/07/2017
CVSS v2 Base Score: 2.6 | Impact Score: 2.9 | Exploitability Score: 4.9
VMScore: 231
Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in the login page of the HTTP interface for the Cisco Wireless Control System (WCS) for Linux and Windows prior to 3.2(51) allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors involving a "malicious URL".

Vulnerable Product Search on Vulmon Subscribe to Product

cisco wireless control system

Vendor Advisories

Cisco Wireless Control System (WCS) contains multiple vulnerabilities which may allow a remote user to: access sensitive configuration information about access points managed by WCS read from and write to arbitrary files on a WCS system log in to a WCS system with a default administrator password execute scr ...