D-Link DIR-815 REV. B (with firmware through DIR-815REVBFIRMWAREPATCH2.07.B01) devices have permission bypass and information disclosure in /htdocs/web/getcfg.php, as demonstrated by a /getcfg.php?a=%0aPOSTSERVICES%3DDEVICE.ACCOUNT%0aAUTHORIZEDGROUP%3D1 request.
D-Link DIR-815 REV. B (with firmware through DIR-815REVBFIRMWAREPATCH2.07.B01) devices have XSS in the RESULT parameter to /htdocs/webinc/js/info.php.
D-Link DIR-815 REV. B (with firmware through DIR-815REVBFIRMWAREPATCH2.07.B01) devices have XSS in the Treturn parameter to /htdocs/webinc/js/bscsmsinbox.php.
UNSUPPORTED WHEN ASSIGNED webinc/js/info.php on D-Link DIR-816L 2.06.B09BETA and DIR-803 1.04.B02 devices allows XSS via the HTTP Referer header. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: this is typically not exploitable because of URL encoding (except in Internet Explorer) and because a web page cannot specify that a client should make an additional HTTP request with an arbitrary Referer header.