First published: Fri Apr 21 2006(Updated: )
Cross-site scripting (XSS) vulnerability in the appliance web user interface in Cisco CiscoWorks Wireless LAN Solution Engine (WLSE) and WLSE Express before 2.13 allows remote attackers to inject arbitrary web script or HTML, possibly via the displayMsg parameter to archiveApplyDisplay.jsp, aka bug ID CSCsc01095.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Wireless LAN Solution Engine | =2.3 | |
Cisco Wireless LAN Solution Engine | =2.6 | |
Cisco Wireless LAN Solution Engine | =2.11 | |
Cisco Wireless LAN Solution Engine | =2.2 | |
Cisco Wireless LAN Solution Engine | =2.4 | |
Cisco Wireless LAN Solution Engine | =2.4 | |
Cisco Wireless LAN Solution Engine | =2.12 | |
Cisco Wireless LAN Solution Engine | =2.10 | |
Cisco Wireless LAN Solution Engine | =2.13 | |
Cisco Wireless LAN Solution Engine | =2.11 | |
Cisco Wireless LAN Solution Engine | =2.1 | |
Cisco Wireless LAN Solution Engine | =2.2 | |
Cisco Wireless LAN Solution Engine | =2.0 | |
Cisco Wireless LAN Solution Engine | =2.7 | |
Cisco Wireless LAN Solution Engine | =2.1 | |
Cisco Wireless LAN Solution Engine | =2.9 | |
Cisco Wireless LAN Solution Engine | =2.5 | |
Cisco Wireless LAN Solution Engine | =2.9 | |
Cisco Wireless LAN Solution Engine | =2.7 | |
Cisco Wireless LAN Solution Engine | =2.8 | |
Cisco Wireless LAN Solution Engine | =2.12 | |
Cisco Wireless LAN Solution Engine | =2.5 | |
Cisco Wireless LAN Solution Engine | =2.0 | |
Cisco Wireless LAN Solution Engine | =2.3 | |
Cisco Wireless LAN Solution Engine | =2.8 | |
Cisco Wireless LAN Solution Engine | =2.6 | |
Cisco Wireless LAN Solution Engine | =2.13 | |
Cisco Wireless LAN Solution Engine | =2.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-1960 is classified as a moderate severity vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2006-1960, update your Cisco Wireless LAN Solution Engine to version 2.13 or later.
CVE-2006-1960 affects multiple versions of Cisco Wireless LAN Solution Engine, specifically versions before 2.13.
CVE-2006-1960 is a cross-site scripting (XSS) vulnerability that allows attackers to inject arbitrary web script or HTML.
Yes, CVE-2006-1960 can be exploited remotely, allowing attackers to potentially compromise users accessing the vulnerable web interface.