CVE-2010-2986

EUVD-2010-2988
Cross-site scripting (XSS) vulnerability in webacs/QuickSearchAction.do in the search feature in the web interface in Cisco Wireless Control System (WCS) before 6.0(194.0) and 7.x before 7.0.164 allows remote attackers to inject arbitrary web script or HTML via the searchText parameter, aka Bug ID CSCtf14288.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 56%
Affected Products (NVD)
VendorProductVersion
ciscowireless_control_system_software
𝑥
≤ 6.0.188.0
ciscowireless_control_system_software
3.2.78.0
ciscowireless_control_system_software
4.0.155.5
ciscowireless_control_system_software
4.1
ciscowireless_control_system_software
4.1.83.0
ciscowireless_control_system_software
4.1.91.0
ciscowireless_control_system_software
4.1.171.0
ciscowireless_control_system_software
4.1.191.xm:xm
ciscowireless_control_system_software
4.1.192.35m:m
ciscowireless_control_system_software
4.1.192.xm:xm
ciscowireless_control_system_software
4.2.62.0
ciscowireless_control_system_software
4.2.62.11
ciscowireless_control_system_software
4.2.81.0
ciscowireless_control_system_software
4.2.97.0
ciscowireless_control_system_software
4.2.110.0
ciscowireless_control_system_software
4.2.128.0
ciscowireless_control_system_software
4.2.130.0
ciscowireless_control_system_software
4.2.173.0
ciscowireless_control_system_software
4.2.176.0
ciscowireless_control_system_software
4.2.209.0
ciscowireless_control_system_software
5.0.56.0
ciscowireless_control_system_software
5.0.56.2
ciscowireless_control_system_software
5.0.148.0
ciscowireless_control_system_software
5.1.64.0
ciscowireless_control_system_software
5.1.65.4
ciscowireless_control_system_software
5.1.151.0
ciscowireless_control_system_software
5.2.110.0
ciscowireless_control_system_software
5.2.125.0
ciscowireless_control_system_software
5.2.130.0
ciscowireless_control_system_software
5.2.148.0
ciscowireless_control_system_software
5.2.157.0
ciscowireless_control_system_software
6.0
ciscowireless_control_system_software
6.0.132.0
ciscowireless_control_system_software
6.0.170.0
ciscowireless_control_system_software
6.0.181.0
ciscowireless_control_system_software
6.0.182.0
ciscowireless_control_system_software
7.0
ciscowireless_control_system_software
7.0.98.0
𝑥
= Vulnerable software versions