PT-2014-3201 · Sitecom+5 · Sitecom Wl-174+6

CVE-2013-6786

·

Publicado

2014-01-16

·

Atualizado

2023-04-26

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Allegro RomPager versions prior to 4.51 ZyXEL P660HW-D1 (affected versions not specified) Huawei MT882 (affected versions not specified) Sitecom WL-174 (affected versions not specified) TP-LINK TD-8816 (affected versions not specified) D-Link DSL-2640R (affected versions not specified) D-Link DSL-2641R (affected versions not specified)
Description A cross-site scripting (XSS) issue exists when the "forbidden author header" protection mechanism is bypassed, allowing remote attackers to inject arbitrary web script or HTML by requesting a nonexistent URI in conjunction with a crafted HTTP Referer header that is not properly handled in a 404 page.
Recommendations For Allegro RomPager versions prior to 4.51, update to version 4.51 or later. For ZyXEL P660HW-D1, Huawei MT882, Sitecom WL-174, TP-LINK TD-8816, and D-Link DSL-2640R and DSL-2641R, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2013-6786

Produtos afetados

Allegro Rompager
D-Link Dsl-2640B
D-Link Dsl-2641R
Huawei Mt882
Sitecom Wl-174
Tp-Link Td-8816
Zyxel P660Hw-D1