PT-2007-6583 · NetGear · Netgear Ssl312 Prosafe Ssl Vpn-Concentrator
Publicado
2007-10-18
·
Atualizado
2017-07-29
·
CVE-2007-5562
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Netgear SSL312 PROSAFE SSL VPN-Concentrator version 25
Description
A cross-site scripting issue exists due to insufficient input validation in the
cgi-bin/welcome login page, allowing remote attackers to inject arbitrary web script or HTML via the err parameter in the context of an error page.Recommendations
For Netgear SSL312 PROSAFE SSL VPN-Concentrator version 25, update the firmware to a version that addresses this issue, ensuring that input validation is properly implemented to prevent arbitrary script injection.
Exploit
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Netgear Ssl312 Prosafe Ssl Vpn-Concentrator