CVE-2010-2826

SQL injection vulnerability in Cisco Wireless Control System (WCS) 6.0.x before 6.0.196.0 allows remote authenticated users to execute arbitrary SQL commands via vectors related to the ORDER BY clause of the Client List screens, aka Bug ID CSCtf37019.

Data: Cisco advisories · Cisco CSAF · NVD CVEs · NVD CPEs · CISA KEV · EPSS

SeverityHIGH
CVSS9.0
EPSS0.33% EPSS medium
CWECWE-89
KEV
Published
Modified

Products with public affected evidence

Product Advisory Affected evidence
Cisco Wireless Control System (WCS) Software cisco-sa-20100811-wcs structured affected CSAF product_status