CVE-2007-6054

Aruba 800 Mobility Controller <2.5.4.18 & <2.4.8.6-FIPS - XSS

Title source: llm

Description

Cross-site scripting (XSS) vulnerability in the login page in the management interface in the Aruba 800 Mobility Controller 2.5.4.18 and earlier, and 2.4.8.6-FIPS and earlier, allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the /screens URI, related to the url variable.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Jan Fry · textremotemultiple
https://www.exploit-db.com/exploits/30771

Scores

EPSS 0.0192
EPSS Percentile 83.1%

Classification

CWE
CWE-79
Status draft

Affected Products (2)

aruba_networks/mc-800
aruba_networks/mc-800

Timeline

Published Nov 20, 2007
Tracked Since Feb 18, 2026