CVE-2013-2671: XSS
Multiple cross-site scripting (XSS) vulnerabilities in the Brother MFC-9970CDW printer with firmware L (1.10) allow remote attackers to inject arbitrary web script or HTML via the (1) id or (2) val parameter to admin/adminmain.html; (3) id, (4) val, or (5) arbitrary parameter name (QUERYSTRING) to admin/profilesettingsnet.html; or (6) kind or (7) arbitrary parameter name (QUERYSTRING) to fax/generalsetup.html, a different vulnerability than CVE-2013-2507 and CVE-2013-2670.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-2671?
CVE-2013-2671 is considered a medium severity vulnerability due to its potential for remote exploitation.
How do I fix CVE-2013-2671?
To mitigate CVE-2013-2671, it is recommended to update the firmware of the Brother MFC-9970CDW printer to the latest version provided by the manufacturer.
What are the main vulnerabilities associated with CVE-2013-2671?
CVE-2013-2671 is associated with multiple cross-site scripting (XSS) vulnerabilities that allow remote attackers to inject arbitrary web scripts or HTML.
Which devices are affected by CVE-2013-2671?
CVE-2013-2671 affects the Brother MFC-9970CDW printer specifically running firmware version L (1.10).
Can CVE-2013-2671 lead to unauthorized access?
Yes, if exploited, CVE-2013-2671 can lead to unauthorized access by allowing attackers to execute scripts within the context of the printer's web interface.