CVE-2013-6786
Cross-site scripting (XSS) vulnerability in Allegro RomPager before 4.51, as used on the ZyXEL P660HW-D1, Huawei MT882, Sitecom WL-174, TP-LINK TD-8816, and D-Link DSL-2640R and DSL-2641R, when the "forbidden author header" protection mechanism is bypassed, allows remote attackers to inject arbitrary web script or HTML by requesting a nonexistent URI in conjunction with a crafted HTTP Referer header that is not properly handled in a 404 page. NOTE: there is no CVE for a "URL redirection" issue that some sources list separately.
- Affected products
- Allegro Rompager, D-Link Dsl-2640B, D-Link Dsl-2641R, Huawei Mt882, Sitecom Wl-174, Tp-Link Td-8816, Zyxel P660Hw-D1
- Allegrosoft Rompager
- ≤ 4.07
- Dlink dsl-2640r
- All versions
- Dlink dsl-2641r
- All versions
- Huawei mt882
- All versions
- Sitecom wl-174
- All versions
- Tp-link td-8816
- All versions
- CVSS 2.0
- 4.3 MEDIUM
- EPSS
- 2.2% (81th percentile)
- Weakness
- CWE-79
- NVD status
- Modified
- Published
- 2014-01-16
CVE-2013-6786 at NVD
2 known exploits for CVE-2013-6786
Proof-of-concept code and exploit modules indexed by Sploitus