Cross-Site Scripting Vulnerabilities in D-Link DSL-G624T Firmware
CVE-2006-5537

Currently unrated

Key Information:

Vendor

D-link

Status
Vendor
CVE Published:
26 October 2006

What is CVE-2006-5537?

The D-Link DSL-G624T firmware 3.00B01T01.YA-C.20060616 is susceptible to multiple cross-site scripting (XSS) vulnerabilities through the web interface. Attackers can exploit these weaknesses by manipulating the 'upnp:settings/state' and 'upnp:settings/connection' parameters, allowing them to inject arbitrary web scripts or HTML. This can lead to unauthorized actions and exposure of sensitive information.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.