{"api_version":"1","generated_at":"2026-04-23T15:18:51+00:00","cve":"CVE-2010-2988","urls":{"html":"https://cve.report/CVE-2010-2988","api":"https://cve.report/api/cve/CVE-2010-2988.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2010-2988","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2010-2988"},"summary":{"title":"CVE-2010-2988","description":"Cross-site scripting (XSS) vulnerability in Cisco Unified Wireless Network (UWN) Solution 7.x before 7.0.98.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CSCtf35333.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2010-08-10 12:23:00","updated_at":"2010-08-10 20:02:00"},"problem_types":["CWE-79"],"metrics":[],"references":[{"url":"http://www.cisco.com/en/US/docs/wireless/controller/release/notes/crn7.0.html","name":"http://www.cisco.com/en/US/docs/wireless/controller/release/notes/crn7.0.html","refsource":"CONFIRM","tags":[],"title":"Release Notes for Cisco Wireless LAN Controllers and Lightweight Access Points for Release 7.0.98.0 - Cisco Systems","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/40827","name":"40827","refsource":"SECUNIA","tags":["Vendor Advisory"],"title":"Cisco Wireless Control System Cross-Site Scripting and SQL Injection Vulnerabilities - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2010-2988","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2010-2988","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2010","cve_id":"2988","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"cisco","cpe5":"unified_wireless_network_solution_software","cpe6":"7.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"2988","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"cisco","cpe5":"unified_wireless_network_solution_software","cpe6":"7.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2010-2988","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site scripting (XSS) vulnerability in Cisco Unified Wireless Network (UWN) Solution 7.x before 7.0.98.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CSCtf35333."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://www.cisco.com/en/US/docs/wireless/controller/release/notes/crn7.0.html","refsource":"CONFIRM","url":"http://www.cisco.com/en/US/docs/wireless/controller/release/notes/crn7.0.html"},{"name":"40827","refsource":"SECUNIA","url":"http://secunia.com/advisories/40827"}]}},"nvd":{"publishedDate":"2010-08-10 12:23:00","lastModifiedDate":"2010-08-10 20:02:00","problem_types":["CWE-79"],"metrics":{"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":4.3},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:cisco:unified_wireless_network_solution_software:7.0:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2010","CveId":"2988","Ordinal":"45241","Title":"CVE-2010-2988","CVE":"CVE-2010-2988","Year":"2010"},"notes":[{"CveYear":"2010","CveId":"2988","Ordinal":"1","NoteData":"Cross-site scripting (XSS) vulnerability in Cisco Unified Wireless Network (UWN) Solution 7.x before 7.0.98.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CSCtf35333.","Type":"Description","Title":null},{"CveYear":"2010","CveId":"2988","Ordinal":"2","NoteData":"2010-08-09","Type":"Other","Title":"Published"}]}}}