CVE-2006-1960

Cross-site scripting (XSS) vulnerability in the appliance web user interface in Cisco CiscoWorks Wireless LAN Solution Engine (WLSE) and WLSE Express before 2.13 allows remote attackers to inject arbitrary web script or HTML, possibly via the displayMsg parameter to archiveApplyDisplay.jsp, aka bug ID CSCsc01095.

Data: Cisco advisories · Cisco CSAF · NVD CVEs · NVD CPEs · CISA KEV · EPSS

SeverityMEDIUM
CVSS5.8
EPSS7.87% EPSS high
CWENVD-CWE-Other
KEV
Published
Modified

Products with public affected evidence

Product Advisory Affected evidence
CiscoWorks Wireless LAN Solution Engine (WLSE) cisco-sa-20060419-wlse structured affected CSAF product_status
CiscoWorks Wireless LAN Solution Engine (WLSE) Express cisco-sa-20060419-wlse structured affected CSAF product_status