First published: Mon Jul 07 2014(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in D-Link DIR-645 Router (Rev. A1) with firmware before 1.04B11 allow remote attackers to inject arbitrary web script or HTML via the (1) deviceid parameter to parentalcontrols/bind.php, (2) RESULT parameter to info.php, or (3) receiver parameter to bsc_sms_send.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
D-Link DIR-645 Firmware | <=1.03 | |
dlink DIR-645 A1 | =a1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-7389 is considered a moderate severity vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2013-7389, update the D-Link DIR-645 Router firmware to version 1.04B11 or later.
CVE-2013-7389 affects D-Link DIR-645 routers running firmware versions prior to 1.04B11.
CVE-2013-7389 allows remote attackers to perform cross-site scripting (XSS) attacks by injecting arbitrary web scripts or HTML.
The vulnerable components in CVE-2013-7389 include the parental controls and info.php scripts, specifically through the deviceid and RESULT parameters.