CVE-2008-1257: XSS
Cross-site scripting (XSS) vulnerability in Forms/DiagGeneral2 on the ZyXEL P-660HW series router allows remote attackers to inject arbitrary web script or HTML via the PingIPAddr parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-1257?
CVE-2008-1257 is classified as a moderate severity vulnerability due to the potential for cross-site scripting attacks.
How do I fix CVE-2008-1257?
To mitigate CVE-2008-1257, it is recommended to apply available firmware updates from ZyXEL that address the XSS vulnerability.
What devices are affected by CVE-2008-1257?
CVE-2008-1257 affects multiple models of ZyXEL P-660HW series routers, including D1, T3, and D3 variants.
What can attackers achieve with CVE-2008-1257?
Attackers exploiting CVE-2008-1257 can inject arbitrary web scripts or HTML, potentially compromising user data and session information.
Is CVE-2008-1257 still a threat today?
While exploitation may be less common today, outdated devices still running vulnerable firmware can remain a target for local or remote attacks.