PT-2008-2835 · Apple+2 · Safari+2

Publicado

2008-03-10

·

Atualizado

2018-10-11

·

CVE-2008-1243

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Linksys WRT300N router version 2.00.20
Description A cross-site scripting issue allows remote attackers to inject arbitrary web script or HTML via the dyndns domain parameter to the default URI when using Mozilla Firefox or Apple Safari.
Recommendations For version 2.00.20, as a temporary workaround, consider restricting access to the default URI until a patch is available. Avoid using the dyndns domain parameter in the affected URI until the issue is resolved.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-1243

Produtos afetados

Safari
Linksys Wrt300N
Firefox