CVE-2012-6007

Cisco Wireless Lan Controller Software - XSS

Title source: rule

Description

Cross-site scripting (XSS) vulnerability in screens/base/web_auth_custom.html on Cisco Wireless LAN Controller (WLC) devices with software 7.2.110.0 allows remote authenticated users to inject arbitrary web script or HTML via the headline parameter, aka Bug ID CSCud65187, a different vulnerability than CVE-2012-5992.

Exploits (1)

exploitdb WORKING POC
by Jacob Holcomb · textdoshardware
https://www.exploit-db.com/exploits/23361

Scores

EPSS 0.0348
EPSS Percentile 87.5%

Details

CWE
CWE-79
Status published
Products (10)
cisco/wireless_lan_controller_software
cisco/2000_wireless_lan_controller
cisco/2100_wireless_lan_controller
cisco/2500_wireless_lan_controller
cisco/4100_wireless_lan_controller
cisco/4400_wireless_lan_controller
cisco/5500_wireless_lan_controller
cisco/7500_wireless_lan_controller
cisco/8500_wireless_lan_controller
n/a/n/a
Published Dec 19, 2012
Tracked Since Feb 18, 2026