PT-2018-17398 · Routers2 · Routers2

Lorenzo Di Fuccia

·

Publicado

2018-01-24

·

Atualizado

2018-03-03

·

CVE-2018-6193

CVSS v3.1

4.7

Média

VetorAV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Routers2 version 2.24
Description A Cross-Site Scripting (XSS) issue was discovered, affecting the rtr GET parameter in a "page=graph" action to the "cgi-bin/routers2.pl" endpoint.
Recommendations For Routers2 version 2.24, consider restricting access to the vulnerable cgi-bin/routers2.pl endpoint until a patch is available. As a temporary workaround, avoid using the rtr parameter in the affected endpoint to minimize the risk of exploitation.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-6193

Produtos afetados

Routers2