Vulnerabilities > Cisco > Wireless LAN Solution Engine > 2.13

DATE CVE VULNERABILITY TITLE RISK
2007-10-12 CVE-2007-5382 Permissions, Privileges, and Access Controls vulnerability in Cisco products
The conversion utility for converting CiscoWorks Wireless LAN Solution Engine (WLSE) 4.1.91.0 and earlier to Cisco Wireless Control System (WCS) creates administrator accounts with default usernames and passwords, which allows remote attackers to gain privileges.
network
low complexity
cisco CWE-264
critical
10.0
2006-04-21 CVE-2006-1961 Local Privilege Escalation vulnerability in Multiple Linux-Based Cisco Products
Cisco CiscoWorks Wireless LAN Solution Engine (WLSE) and WLSE Express before 2.13, Hosting Solution Engine (HSE) and User Registration Tool (URT) before 20060419, and all versions of Ethernet Subscriber Solution Engine (ESSE) and CiscoWorks2000 Service Management Solution (SMS) allow local users to gain Linux shell access via shell metacharacters in arguments to the "show" command in the application's command line interface (CLI), aka bug ID CSCsd21502 (WLSE), CSCsd22861 (URT), and CSCsd22859 (HSE).
network
low complexity
cisco
7.5
2006-04-21 CVE-2006-1960 Cross-Site Scripting vulnerability in Cisco Wireless Lan Solution Engine ArchiveApplyDisplay.JSP
Cross-site scripting (XSS) vulnerability in the appliance web user interface in Cisco CiscoWorks Wireless LAN Solution Engine (WLSE) and WLSE Express before 2.13 allows remote attackers to inject arbitrary web script or HTML, possibly via the displayMsg parameter to archiveApplyDisplay.jsp, aka bug ID CSCsc01095.
network
cisco
5.8