Cross-site Scripting Vulnerability in Cisco Wireless Control System
CVE-2010-2986

Currently unrated

Key Information:

Vendor
Cisco
Vendor
CVE Published:
10 August 2010

Summary

A cross-site scripting (XSS) vulnerability exists in the search feature of the web interface of Cisco Wireless Control System. This flaw allows remote attackers to inject arbitrary web scripts or HTML through the 'searchText' parameter. The affected versions include Cisco Wireless Control System prior to 6.0(194.0) and all 7.x versions before 7.0.164. Successful exploitation can lead to unauthorized actions being executed in the context of the user’s session.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.