PT-2008-2835 · Apple+2 · Safari+2
Published
2008-03-10
·
Updated
2018-10-11
·
CVE-2008-1243
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Linksys WRT300N router version 2.00.20
Description
A cross-site scripting issue allows remote attackers to inject arbitrary web script or HTML via the
dyndns domain parameter to the default URI when using Mozilla Firefox or Apple Safari.Recommendations
For version 2.00.20, as a temporary workaround, consider restricting access to the default URI until a patch is available. Avoid using the
dyndns domain parameter in the affected URI until the issue is resolved.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Safari
Linksys Wrt300N
Firefox