Multiple D-Link Products Multiple Cross-Site Scripting and Denial of Service Vulnerabilities
BID:28439
Info
Multiple D-Link Products Multiple Cross-Site Scripting and Denial of Service Vulnerabilities
| Bugtraq ID: | 28439 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-1266 CVE-2008-1253 CVE-2008-1258 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 25 2008 12:00AM |
| Updated: | Mar 26 2008 04:10PM |
| Credit: | Gareth Heyes, Jonas, and laurent discovered these vulnerabilities. |
| Vulnerable: |
D-Link DSL-G604T D-Link DI-604 D-Link DI-524 0 |
| Not Vulnerable: | |
Discussion
Multiple D-Link Products Multiple Cross-Site Scripting and Denial of Service Vulnerabilities
Multiple D-Link products are prone to multiple cross-site scripting and denial-of-service vulnerabilities because the devices fail to properly handle user-supplied input.
An attacker may leverage these issues to cause denial-of-service conditions or to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Multiple D-Link products are prone to multiple cross-site scripting and denial-of-service vulnerabilities because the devices fail to properly handle user-supplied input.
An attacker may leverage these issues to cause denial-of-service conditions or to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Exploit / POC
Multiple D-Link Products Multiple Cross-Site Scripting and Denial of Service Vulnerabilities
To exploit the cross-site scripting issues, an attacker must entice an unsuspecting user to follow a malicious URI. To exploit the denial-of-service issues, attackers can use readily available tools.
To exploit the cross-site scripting issues, an attacker must entice an unsuspecting user to follow a malicious URI. To exploit the denial-of-service issues, attackers can use readily available tools.
Solution / Fix
Multiple D-Link Products Multiple Cross-Site Scripting and Denial of Service Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Multiple D-Link Products Multiple Cross-Site Scripting and Denial of Service Vulnerabilities
References:
References:
- Router Hacking Challenge Homepage (GNUCITIZEN)
- Vendor Homepage (D-Link)