CVE-2012-5991
Cisco Wireless LAN Controller Software 7.2.110.0 - Authenticated Denial of Service via web_auth_custom.html Button Click
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2012-5991.
AI-analyzed exploit summary The exploit demonstrates a chained attack against Cisco Wireless Lan Controller (WLC) 7.2.110.0, combining CSRF, persistent XSS, and a DoS vulnerability. It includes functional HTML/JS code to add an admin user via CSRF and trigger XSS, along with a DoS payload that crashes the WLC via a crafted GET request.
Description
screens/base/web_auth_custom.html on Cisco Wireless LAN Controller (WLC) devices with software 7.2.110.0 allows remote authenticated users to cause a denial of service (device reload) via a certain buttonClicked value in an internal webauth_type request, aka Bug ID CSCud50209.
Exploits (1)
The exploit demonstrates a chained attack against Cisco Wireless Lan Controller (WLC) 7.2.110.0, combining CSRF, persistent XSS, and a DoS vulnerability. It includes functional HTML/JS code to add an admin user via CSRF and trigger XSS, along with a DoS payload that crashes the WLC via a crafted GET request.