First published: Fri Aug 25 2017(Updated: )
The web/web_file/fb_publish.php script in D-Link DNS-320L before 1.04b12 and DNS-327L before 1.03b04 Build0119 does not authenticate requests, which allows remote attackers to obtain arbitrary photos and publish them to an arbitrary Facebook profile via a target album_id and access_token.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
D-link Dns-327l Firmware | <=1.02 | |
Dlink Dns-327l | ||
<=1.03b04 | ||
Dlink Dns-320l |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.