Description
SQL injection vulnerability in Cisco Wireless Control System (WCS) 6.0.x before 6.0.196.0 allows remote authenticated users to execute arbitrary SQL commands via vectors related to the ORDER BY clause of the Client List screens, aka Bug ID CSCtf37019.
References (1)
Core 1
Core References
Vendor Advisory vendor-advisory
x_refsource_cisco
http://www.cisco.com/en/US/products/products_security_advisory09186a0080b4091e.shtml
Scores
EPSS
0.0134
EPSS Percentile
68.3%
Details
CWE
CWE-89
Status
published
Products (6)
cisco/wireless_control_system_software
6.0
cisco/wireless_control_system_software
6.0.132.0
cisco/wireless_control_system_software
6.0.170.0
cisco/wireless_control_system_software
6.0.181.0
cisco/wireless_control_system_software
6.0.182.0
cisco/wireless_control_system_software
< 6.0.188.0
Published
Aug 17, 2010
Tracked Since
Feb 18, 2026