Cisco Wireless Control System Multiple Security Vulnerabilities
BID:18701
CVE-2006-3285 | CVE-2006-3286 | CVE-2006-3287 | CVE-2006-3288 | CVE-2006-3289 | CVE-2006-3290 |Info
Cisco Wireless Control System Multiple Security Vulnerabilities
| Bugtraq ID: | 18701 |
| Class: | Unknown |
| CVE: |
CVE-2006-3289 CVE-2006-3290 CVE-2006-3287 CVE-2006-3288 CVE-2006-3285 CVE-2006-3286 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 28 2006 12:00AM |
| Updated: | Jun 04 2007 07:50PM |
| Credit: | These issues were disclosed by the vendor. |
| Vulnerable: |
Cisco Wireless Control System Software 4.0 Cisco Wireless Control System Software 3.2 |
| Not Vulnerable: | |
Discussion
Cisco Wireless Control System Multiple Security Vulnerabilities
Cisco Wireless Control System is prone to multiple security vulnerabilities.
The following issues have been disclosed:
- Authorization-bypass vulnerability due to multiple hardcoded username and password pairs
- Arbitrary file access vulnerability
- Cross-site scripting vulnerability
- Information-disclosure vulnerability
An attacker can exploit these issues to retrieve potentially sensitive information, overwrite files, perform cross-site scripting attacks, and gain unauthorized access; other attacks are also possible.
Cisco Wireless Control System is prone to multiple security vulnerabilities.
The following issues have been disclosed:
- Authorization-bypass vulnerability due to multiple hardcoded username and password pairs
- Arbitrary file access vulnerability
- Cross-site scripting vulnerability
- Information-disclosure vulnerability
An attacker can exploit these issues to retrieve potentially sensitive information, overwrite files, perform cross-site scripting attacks, and gain unauthorized access; other attacks are also possible.
Exploit / POC
Cisco Wireless Control System Multiple Security Vulnerabilities
These issues do not require exploit code, but only access to the affected application.
Attackers can exploit the cross-site scripting issue by tricking a victim user into following a malicious URI.
These issues do not require exploit code, but only access to the affected application.
Attackers can exploit the cross-site scripting issue by tricking a victim user into following a malicious URI.
Solution / Fix
Cisco Wireless Control System Multiple Security Vulnerabilities
Solution:
The vendor has released updates to address these issues. Please contact the vendor for details.
Solution:
The vendor has released updates to address these issues. Please contact the vendor for details.
References
Cisco Wireless Control System Multiple Security Vulnerabilities
References:
References: