PT-2007-6583 · NetGear · Netgear Ssl312 Prosafe Ssl Vpn-Concentrator
Published
2007-10-18
·
Updated
2017-07-29
·
CVE-2007-5562
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Netgear SSL312 PROSAFE SSL VPN-Concentrator version 25
Description
A cross-site scripting issue exists due to insufficient input validation in the
cgi-bin/welcome login page, allowing remote attackers to inject arbitrary web script or HTML via the err parameter in the context of an error page.Recommendations
For Netgear SSL312 PROSAFE SSL VPN-Concentrator version 25, update the firmware to a version that addresses this issue, ensuring that input validation is properly implemented to prevent arbitrary script injection.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Netgear Ssl312 Prosafe Ssl Vpn-Concentrator