PT-2014-3201 · D Link +5 · D-Link Dsl-2641R +6

Published

2014-01-16

·

Updated

2023-04-26

·

CVE-2013-6786

CVSS v2.0
4.3
VectorAV:N/AC:M/Au:N/C:N/I:P/A:N

Name of the Vulnerable Software and Affected Versions:

Allegro RomPager versions prior to 4.51

ZyXEL P660HW-D1 (affected versions not specified)

Huawei MT882 (affected versions not specified)

Sitecom WL-174 (affected versions not specified)

TP-LINK TD-8816 (affected versions not specified)

D-Link DSL-2640R (affected versions not specified)

D-Link DSL-2641R (affected versions not specified)

Description:

A cross-site scripting (XSS) issue exists when the "forbidden author header" protection mechanism is bypassed, allowing remote attackers to inject arbitrary web script or HTML by requesting a nonexistent URI in conjunction with a crafted HTTP Referer header that is not properly handled in a 404 page.

Recommendations:

For Allegro RomPager versions prior to 4.51, update to version 4.51 or later.

For ZyXEL P660HW-D1, Huawei MT882, Sitecom WL-174, TP-LINK TD-8816, and D-Link DSL-2640R and DSL-2641R, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

CVE-2013-6786

Affected Products

Allegro Rompager
D-Link Dsl-2640B
D-Link Dsl-2641R
Huawei Mt882
Sitecom Wl-174
Tp-Link Td-8816
Zyxel P660Hw-D1