peter bassill · operator
$ cve CVE-2012-6007 JSON

CVE-2012-6007 EXPLOIT

4.3
MEDIUM · CVSS 2.0 · EPSS 3.7% (pctl 89)

Patch early

A public exploit exists.

Description

Cross-site scripting (XSS) vulnerability in screens/base/web_auth_custom.html on Cisco Wireless LAN Controller (WLC) devices with software 7.2.110.0 allows remote authenticated users to inject arbitrary web script or HTML via the headline parameter, aka Bug ID CSCud65187, a different vulnerability than CVE-2012-5992.

Scoring

CVSS4.3 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS3.66% — more likely to be exploited than 89% of all CVEs
WeaknessCWE-79
On CISA KEVno
Public exploityes
Published2012-12-19
Last modified2026-06-16

Affected (9)

VendorProduct
cisco2000 wireless lan controller
cisco2100 wireless lan controller
cisco2500 wireless lan controller
cisco4100 wireless lan controller
cisco4400 wireless lan controller
cisco5500 wireless lan controller
cisco7500 wireless lan controller
cisco8500 wireless lan controller
ciscowireless lan controller software

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD