CVE-2006-3290
Published Jun 28, 2006
Last updated 7 years ago
Overview
- Description
- HTTP server in Cisco Wireless Control System (WCS) for Linux and Windows before 3.2(51) stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain usernames and directory paths via a direct URL request.
- Source
- cve@mitre.org
- NVD status
- Modified
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 5
- Impact score
- 2.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:N/A:N
Weaknesses
- nvd@nist.gov
- NVD-CWE-Other
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:cisco:wireless_control_system:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1B0A192A-AC2C-494D-9AFD-EB4C5DA536B4", "versionEndIncluding": "3.2\\(51\\)" } ], "operator": "OR" } ] } ]