CVE-2010-2826

Published Aug 17, 2010

Last updated 3 months ago

Overview

Description
SQL injection vulnerability in Cisco Wireless Control System (WCS) 6.0.x before 6.0.196.0 allows remote authenticated users to execute arbitrary SQL commands via vectors related to the ORDER BY clause of the Client List screens, aka Bug ID CSCtf37019.
Source
ykramarz@cisco.com
NVD status
Modified

Risk scores

CVSS 2.0

Type
Primary
Base score
9
Impact score
10
Exploitability score
8
Vector string
AV:N/AC:L/Au:S/C:C/I:C/A:C

Weaknesses

nvd@nist.gov
CWE-89

Social media

Hype score
Not currently trending

Configurations