Description
Cross-site scripting (XSS) vulnerability in screens/base/web_auth_custom.html on Cisco Wireless LAN Controller (WLC) devices with software 7.2.110.0 allows remote authenticated users to inject arbitrary web script or HTML via the headline parameter, aka Bug ID CSCud65187, a different vulnerability than CVE-2012-5992.
Exploits (1)
References (1)
Core 1
Core References
Exploit x_refsource_misc
http://infosec42.blogspot.dk/2012/12/cisco-wlc-csrf-dos-and-persistent-xss.html
Scores
EPSS
0.0348
EPSS Percentile
87.7%
Details
CWE
CWE-79
Status
published
Products (9)
cisco/2000_wireless_lan_controller
cisco/2100_wireless_lan_controller
cisco/2500_wireless_lan_controller
cisco/4100_wireless_lan_controller
cisco/4400_wireless_lan_controller
cisco/5500_wireless_lan_controller
cisco/7500_wireless_lan_controller
cisco/8500_wireless_lan_controller
cisco/wireless_lan_controller_software
7.2.110.0
Published
Dec 19, 2012
Tracked Since
Feb 18, 2026