D-Link DSL-320B Multiple Information Disclosure Vulnerabilities and HTML Injection Vulnerability
BID:59665
Info
D-Link DSL-320B Multiple Information Disclosure Vulnerabilities and HTML Injection Vulnerability
| Bugtraq ID: | 59665 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 06 2013 12:00AM |
| Updated: | May 06 2013 12:00AM |
| Credit: | Michael Messner |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
D-Link DSL-320B Multiple Information Disclosure Vulnerabilities and HTML Injection Vulnerability
D-Link DSL-320B is prone to the following security vulnerabilities:
1. An HTML-injection vulnerability
2. Multiple information-disclosure vulnerabilities
Exploiting these issues could allow an attacker disclose sensitive information, execute HTML and arbitrary script code in the browser of an unsuspecting user in the context of the affected site, and steal cookie-based authentication credentials in the context of the affected device.
D-Link DSL-320B is prone to the following security vulnerabilities:
1. An HTML-injection vulnerability
2. Multiple information-disclosure vulnerabilities
Exploiting these issues could allow an attacker disclose sensitive information, execute HTML and arbitrary script code in the browser of an unsuspecting user in the context of the affected site, and steal cookie-based authentication credentials in the context of the affected device.
Exploit / POC
D-Link DSL-320B Multiple Information Disclosure Vulnerabilities and HTML Injection Vulnerability
An attacker can exploit these issues using a web browser.
The following example URIs are available:
An attacker can exploit these issues using a web browser.
The following example URIs are available:
Solution / Fix
D-Link DSL-320B Multiple Information Disclosure Vulnerabilities and HTML Injection Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
D-Link DSL-320B Multiple Information Disclosure Vulnerabilities and HTML Injection Vulnerability
References:
References:
- D-Link Homepage (D-Link)