Vulnerabilities > Cisco > Hosting Solution Engine > 1.7

DATE CVE VULNERABILITY TITLE RISK
2006-04-21 CVE-2006-1961 Local Privilege Escalation vulnerability in Multiple Linux-Based Cisco Products
Cisco CiscoWorks Wireless LAN Solution Engine (WLSE) and WLSE Express before 2.13, Hosting Solution Engine (HSE) and User Registration Tool (URT) before 20060419, and all versions of Ethernet Subscriber Solution Engine (ESSE) and CiscoWorks2000 Service Management Solution (SMS) allow local users to gain Linux shell access via shell metacharacters in arguments to the "show" command in the application's command line interface (CLI), aka bug ID CSCsd21502 (WLSE), CSCsd22861 (URT), and CSCsd22859 (HSE).
network
low complexity
cisco
7.5
2004-06-01 CVE-2004-0391 Unspecified vulnerability in Cisco products
Cisco Wireless LAN Solution Engine (WLSE) 2.0 through 2.5 and Hosting Solution Engine (HSE) 1.7 through 1.7.3 have a hardcoded username and password, which allows remote attackers to add new users, modify existing users, and change configuration.
network
low complexity
cisco
critical
10.0