Cisco Wireless Control System Cross Site Scripting Vulnerability
BID:42216
Info
Cisco Wireless Control System Cross Site Scripting Vulnerability
| Bugtraq ID: | 42216 |
| Class: | Input Validation Error |
| CVE: |
CVE-2010-2986 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 04 2010 12:00AM |
| Updated: | Apr 13 2015 09:02PM |
| Credit: | Tom Neaves |
| Vulnerable: |
Cisco Wireless Control System 6.0.181.0 |
| Not Vulnerable: | |
Discussion
Cisco Wireless Control System Cross Site Scripting Vulnerability
The Cisco Wireless Control System is prone to a cross-site scripting vulnerability because the application fails to sufficiently sanitize user-supplied input.
Exploiting this vulnerability could allow an attacker to perform cross-site scripting attacks on unsuspecting users in the context of the affected website. As a result, the attacker may be able to steal cookie-based authentication credentials and launch other attacks.
Cisco Wireless Control System versions 6.0.181.0 and prior are vulnerable.
The Cisco Wireless Control System is prone to a cross-site scripting vulnerability because the application fails to sufficiently sanitize user-supplied input.
Exploiting this vulnerability could allow an attacker to perform cross-site scripting attacks on unsuspecting users in the context of the affected website. As a result, the attacker may be able to steal cookie-based authentication credentials and launch other attacks.
Cisco Wireless Control System versions 6.0.181.0 and prior are vulnerable.
Exploit / POC
Cisco Wireless Control System Cross Site Scripting Vulnerability
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
Solution / Fix
Cisco Wireless Control System Cross Site Scripting Vulnerability
Solution:
The vendor released updates to address this issue. Please contact the vendor for information on how to obtain and apply these updates.
Solution:
The vendor released updates to address this issue. Please contact the vendor for information on how to obtain and apply these updates.
References
Cisco Wireless Control System Cross Site Scripting Vulnerability
References:
References: