D-Link DIR-655 Multiple Security Vulnerabilities
BID:71772
Info
D-Link DIR-655 Multiple Security Vulnerabilities
| Bugtraq ID: | 71772 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-9518 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 22 2014 12:00AM |
| Updated: | Mar 08 2015 04:04PM |
| Credit: | Keven Jiang |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
D-Link DIR-655 Multiple Security Vulnerabilities
D-Link DIR-655 is prone to cross-site scripting, security-bypass, and information-disclosure vulnerabilities.
Attackers can exploit these issues to execute arbitrary script code in the context of the website, steal cookie-based authentication information, disclose sensitive information, or bypass the authentication mechanism and gain unauthorized access.
D-Link DIR-655 is prone to cross-site scripting, security-bypass, and information-disclosure vulnerabilities.
Attackers can exploit these issues to execute arbitrary script code in the context of the website, steal cookie-based authentication information, disclose sensitive information, or bypass the authentication mechanism and gain unauthorized access.
Exploit / POC
D-Link DIR-655 Multiple Security Vulnerabilities
An attacker can exploit these issues using a browser. To exploit a cross-site scripting issue, the attacker must entice an unsuspecting victim to follow a malicious URI.
The researcher who discovered these issues has created a proof-of-concept. Please see the references for more information.
An attacker can exploit these issues using a browser. To exploit a cross-site scripting issue, the attacker must entice an unsuspecting victim to follow a malicious URI.
The researcher who discovered these issues has created a proof-of-concept. Please see the references for more information.
Solution / Fix
D-Link DIR-655 Multiple Security Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.