PT-2009-1754 · Linksys · Linksys Wrt160N
Published
2009-02-25
·
Updated
2017-08-17
·
CVE-2008-6280
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
Linksys WRT160N (affected versions not specified)
Description:
A cross-site scripting (XSS) issue exists, allowing remote attackers to inject arbitrary web script or HTML via the
action parameter in a DHCP Static operation on the apply.cgi page.Recommendations:
For the Linksys WRT160N, avoid using the
action parameter in the DHCP Static operation on the apply.cgi page until a fix is available. As a temporary workaround, consider restricting access to the apply.cgi page to minimize the risk of exploitation.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linksys Wrt160N