5
CVSSv2

CVE-2006-3290

Published: 28/06/2006 Updated: 20/07/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

HTTP server in Cisco Wireless Control System (WCS) for Linux and Windows prior to 3.2(51) stores sensitive information under the web root with insufficient access control, which allows remote malicious users to obtain usernames and directory paths via a direct URL request.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco wireless control system

Vendor Advisories

Cisco Wireless Control System (WCS) contains multiple vulnerabilities which may allow a remote user to: access sensitive configuration information about access points managed by WCS read from and write to arbitrary files on a WCS system log in to a WCS system with a default administrator password execute scr ...