CVE-2007-3574: XSS
Multiple cross-site scripting (XSS) vulnerabilities in setup.cgi on the Cisco Linksys WAG54GS Wireless-G ADSL Gateway with 1.00.06 firmware allow remote attackers to inject arbitrary web script or HTML via the (1) c4trapip, (2) devname, (3) snmpgetcomm, or (4) snmpsetcomm parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-3574?
CVE-2007-3574 has a medium severity rating due to its cross-site scripting vulnerabilities allowing remote scripts injection.
How do I fix CVE-2007-3574?
To fix CVE-2007-3574, update the Cisco Linksys WAG54GS Wireless-G ADSL Gateway to a patched firmware version.
What are the affected devices in CVE-2007-3574?
CVE-2007-3574 affects the Cisco Linksys WAG54GS Wireless-G ADSL Gateway running firmware version 1.00.06.
Can CVE-2007-3574 be exploited by an unauthenticated user?
Yes, CVE-2007-3574 can be exploited by unauthenticated users via specially crafted URLs.
What parameters are vulnerable in CVE-2007-3574?
CVE-2007-3574 is vulnerable due to the parameters c4_trap_ip_, devname, snmp_getcomm, and snmp_setcomm.