CVE-2006-1960
Summary
| CVE | CVE-2006-1960 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-04-21 10:02:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Cross-site scripting (XSS) vulnerability in the appliance web user interface in Cisco CiscoWorks Wireless LAN Solution Engine (WLSE) and WLSE Express before 2.13 allows remote attackers to inject arbitrary web script or HTML, possibly via the displayMsg parameter to archiveApplyDisplay.jsp, aka bug ID CSCsc01095. |
Risk And Classification
Primary CVSS: v2.0 5.8 from [email protected]
AV:N/AC:M/Au:N/C:P/I:P/A:N
EPSS: 0.078720000 probability, percentile 0.920280000 (date 2026-04-20)
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:P/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Cisco | Wireless Lan Solution Engine | 2.0 | All | All | All |
| Application | Cisco | Wireless Lan Solution Engine | 2.0 | All | express | All |
| Application | Cisco | Wireless Lan Solution Engine | 2.1 | All | All | All |
| Application | Cisco | Wireless Lan Solution Engine | 2.1 | All | express | All |
| Application | Cisco | Wireless Lan Solution Engine | 2.10 | All | All | All |
| Application | Cisco | Wireless Lan Solution Engine | 2.10 | All | express | All |
| Application | Cisco | Wireless Lan Solution Engine | 2.11 | All | All | All |
| Application | Cisco | Wireless Lan Solution Engine | 2.11 | All | express | All |
| Application | Cisco | Wireless Lan Solution Engine | 2.12 | All | All | All |
| Application | Cisco | Wireless Lan Solution Engine | 2.12 | All | express | All |
| Application | Cisco | Wireless Lan Solution Engine | 2.13 | All | All | All |
| Application | Cisco | Wireless Lan Solution Engine | 2.13 | All | express | All |
| Application | Cisco | Wireless Lan Solution Engine | 2.2 | All | All | All |
| Application | Cisco | Wireless Lan Solution Engine | 2.2 | All | express | All |
| Application | Cisco | Wireless Lan Solution Engine | 2.3 | All | All | All |
| Application | Cisco | Wireless Lan Solution Engine | 2.3 | All | express | All |
| Application | Cisco | Wireless Lan Solution Engine | 2.4 | All | All | All |
| Application | Cisco | Wireless Lan Solution Engine | 2.4 | All | express | All |
| Application | Cisco | Wireless Lan Solution Engine | 2.5 | All | All | All |
| Application | Cisco | Wireless Lan Solution Engine | 2.5 | All | express | All |
| Application | Cisco | Wireless Lan Solution Engine | 2.6 | All | All | All |
| Application | Cisco | Wireless Lan Solution Engine | 2.6 | All | express | All |
| Application | Cisco | Wireless Lan Solution Engine | 2.7 | All | All | All |
| Application | Cisco | Wireless Lan Solution Engine | 2.7 | All | express | All |
| Application | Cisco | Wireless Lan Solution Engine | 2.8 | All | All | All |
| Application | Cisco | Wireless Lan Solution Engine | 2.8 | All | express | All |
| Application | Cisco | Wireless Lan Solution Engine | 2.9 | All | All | All |
| Application | Cisco | Wireless Lan Solution Engine | 2.9 | All | express | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Page not found - CyberCX | Australia | af854a3a-2127-422b-91ae-364da2661108 | www.assurance.com.au | |
| Cisco Wireless Lan Solution Engine ArchiveApplyDisplay.JSP Cross-Site Scripting Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Cisco - Networking, Cloud, and Cybersecurity Solutions | af854a3a-2127-422b-91ae-364da2661108 | www.cisco.com | Patch |
| Cisco WLSE Privilege Escalation and Cross-Site Scripting - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Patch, Vendor Advisory |
| CiscoWorks Wireless LAN Solution Engine Cross-Site Scripting Flaw Yields Administrative Privileges and Command Line Bug Lets Remote Authenticated Users Gain Shell Access - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | Patch |
| www.osvdb.org/24812 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.