CVE-2007-6054: XSS
Cross-site scripting (XSS) vulnerability in the login page in the management interface in the Aruba 800 Mobility Controller 2.5.4.18 and earlier, and 2.4.8.6-FIPS and earlier, allows remote attackers to inject arbitrary web script or HTML via the PATHINFO to the /screens URI, related to the url variable.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-6054?
CVE-2007-6054 has a medium severity rating due to its potential for cross-site scripting attacks.
How do I fix CVE-2007-6054?
To fix CVE-2007-6054, upgrade the Aruba 800 Mobility Controller to versions above 2.5.4.18 and 2.4.8.6-FIPS.
What systems are affected by CVE-2007-6054?
CVE-2007-6054 affects Aruba 800 Mobility Controller versions 2.5.4.18 and earlier, as well as 2.4.8.6-FIPS and earlier.
What types of attacks can exploiting CVE-2007-6054 facilitate?
Exploiting CVE-2007-6054 can facilitate cross-site scripting (XSS) attacks allowing injection of arbitrary web scripts or HTML.
Who can exploit CVE-2007-6054?
Remote attackers can exploit CVE-2007-6054 due to insufficient validation of user input on the management interface.