Multiple Cross-Site Scripting Vulnerabilities in D-Link DIR-645 Router
CVE-2013-7389
Currently unrated
What is CVE-2013-7389?
The D-Link DIR-645 Router (Rev. A1), with firmware versions earlier than 1.04B11, contains multiple cross-site scripting (XSS) vulnerabilities. These flaws allow remote attackers to inject arbitrary web scripts or HTML into the device. The vulnerable parameters include 'deviceid' in the parental controls functionality, 'RESULT' in the info.php script, and 'receiver' in the bsc_sms_send.php handler. Exploitation of these vulnerabilities could facilitate unauthorized actions on behalf of users, rendering their sensitive information susceptible to interception and manipulation.