PT-2008-2835 · Apple+2 · Safari+2

Published

2008-03-10

·

Updated

2018-10-11

·

CVE-2008-1243

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Linksys WRT300N router version 2.00.20
Description A cross-site scripting issue allows remote attackers to inject arbitrary web script or HTML via the dyndns domain parameter to the default URI when using Mozilla Firefox or Apple Safari.
Recommendations For version 2.00.20, as a temporary workaround, consider restricting access to the default URI until a patch is available. Avoid using the dyndns domain parameter in the affected URI until the issue is resolved.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-1243

Affected Products

Safari
Linksys Wrt300N
Firefox