CVE-2008-6280
Cross-site scripting (XSS) vulnerability in apply.cgi on the Linksys WRT160N allows remote attackers to inject arbitrary web script or HTML via the action parameter in a DHCP_Static operation.
- Affected products
- Linksys Wrt160N
- Cisco wrt160n
- All versions
- Fix
- Available
- CVSS 2.0
- 4.3 MEDIUM
- EPSS
- 6.9% (94th percentile)
- Weakness
- CWE-79
- NVD status
- Modified
- Published
- 2009-02-25
CVE-2008-6280 at NVD
1 known exploit for CVE-2008-6280
Proof-of-concept code and exploit modules indexed by Sploitus