First published: Mon Aug 13 2007(Updated: )
Cross-site scripting (XSS) vulnerability in Forms/General_1 in the management interface in ZyNOS firmware 3.62(WK.6) on the Zyxel Zywall 2 device allows remote authenticated administrators to inject arbitrary web script or HTML via the sysSystemName parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ZyXEL ZyNOS firmware | =3.62 | |
Zyxel Zywall 2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-4318 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
To remediate CVE-2007-4318, update the ZyNOS firmware to the latest version that addresses the vulnerability.
CVE-2007-4318 specifically affects devices running ZyNOS firmware version 3.62 and Zyxel Zywall 2 systems.
Exploitation of CVE-2007-4318 allows remote authenticated administrators to inject malicious web scripts or HTML into the management interface.
Remote authenticated administrators using Zyxel devices with the affected firmware versions are vulnerable to CVE-2007-4318.