PT-2014-3201 · Sitecom+5 · Sitecom Wl-174+6

Published

2014-01-16

·

Updated

2023-04-26

·

CVE-2013-6786

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Allegro RomPager versions prior to 4.51 ZyXEL P660HW-D1 (affected versions not specified) Huawei MT882 (affected versions not specified) Sitecom WL-174 (affected versions not specified) TP-LINK TD-8816 (affected versions not specified) D-Link DSL-2640R (affected versions not specified) D-Link DSL-2641R (affected versions not specified)
Description A cross-site scripting (XSS) issue exists when the "forbidden author header" protection mechanism is bypassed, allowing remote attackers to inject arbitrary web script or HTML by requesting a nonexistent URI in conjunction with a crafted HTTP Referer header that is not properly handled in a 404 page.
Recommendations For Allegro RomPager versions prior to 4.51, update to version 4.51 or later. For ZyXEL P660HW-D1, Huawei MT882, Sitecom WL-174, TP-LINK TD-8816, and D-Link DSL-2640R and DSL-2641R, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

CVE-2013-6786

Affected Products

Allegro Rompager
D-Link Dsl-2640B
D-Link Dsl-2641R
Huawei Mt882
Sitecom Wl-174
Tp-Link Td-8816
Zyxel P660Hw-D1