First published: Mon Mar 10 2008(Updated: )
Cross-site scripting (XSS) vulnerability in cgi-bin/webcm on the D-Link DSL-G604T router allows remote attackers to inject arbitrary web script or HTML via the var:category parameter, as demonstrated by a request for advanced/portforw.htm on the fwan page.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
D-Link DSL-G604T |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-1253 is classified as a moderate severity cross-site scripting (XSS) vulnerability.
To fix CVE-2008-1253, it is recommended to update the firmware of the D-Link DSL-G604T router to the latest version provided by the manufacturer.
CVE-2008-1253 can allow remote attackers to inject malicious scripts, potentially leading to unauthorized access and data theft.
CVE-2008-1253 affects users of the D-Link DSL-G604T router who have not implemented adequate security measures.
Attackers can leverage CVE-2008-1253 to conduct XSS attacks, which may include stealing session cookies or redirecting users to malicious sites.