CVE-2015-0151: XSS
Published Apr 12, 2018
·Updated
Cross-site request forgery (CSRF) vulnerability in D-Link DIR-815 devices with firmware before 2.07.B01 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.
Affected Software
2 affected components
Dlink Dir-815 Firmware<2.07.b01
Dlink Dir-815
Event History
Apr 12, 2018
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is CVE-2015-0151?
CVE-2015-0151 is a cross-site request forgery (CSRF) vulnerability in D-Link DIR-815 devices.
2
How does CVE-2015-0151 affect D-Link DIR-815 devices?
CVE-2015-0151 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.
3
What is the severity of CVE-2015-0151?
CVE-2015-0151 has a severity rating of 8.8 (high).
4
Which software versions are affected by CVE-2015-0151?
D-Link DIR-815 devices with firmware before 2.07.B01 are affected by CVE-2015-0151.
5
How can I fix CVE-2015-0151?
To fix CVE-2015-0151, update your D-Link DIR-815 device firmware to version 2.07.B01 or newer.