ID

VAR-200809-0483


TITLE

Multiple SAGEM F@st Routers DHCP Hostname HTML Injection Vulnerability

Trust: 0.3

sources: BID: 31331

DESCRIPTION

Multiple SAGEM F@st routers are prone to an HTML-injection vulnerability because they fail to sufficiently sanitize user-supplied input data. Attacker-supplied HTML and script code would run in the context of the web interface of the affected device, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks are also possible. The issue affects SAGEM F@st routers 1200, 1240, 1400, 1400W, 1500, 1500-WG, and 2404.

Trust: 0.3

sources: BID: 31331

AFFECTED PRODUCTS

vendor:sagemmodel:f@stscope:eqversion:24040

Trust: 0.3

vendor:sagemmodel:f@st 1500-wgscope:eqversion:0

Trust: 0.3

vendor:sagemmodel:f@stscope:eqversion:15000

Trust: 0.3

vendor:sagemmodel:f@st 1400wscope:eqversion:0

Trust: 0.3

vendor:sagemmodel:f@stscope:eqversion:14000

Trust: 0.3

vendor:sagemmodel:f@stscope:eqversion:12400

Trust: 0.3

vendor:sagemmodel:f@stscope:eqversion:12000

Trust: 0.3

sources: BID: 31331

THREAT TYPE

network

Trust: 0.3

sources: BID: 31331

TYPE

Input Validation Error

Trust: 0.3

sources: BID: 31331

EXTERNAL IDS

db:BIDid:31331

Trust: 0.3

sources: BID: 31331

REFERENCES

url:http://www.sagem.com/

Trust: 0.3

sources: BID: 31331

CREDITS

Underz0ne Crew

Trust: 0.3

sources: BID: 31331

SOURCES

db:BIDid:31331

LAST UPDATE DATE

2022-05-17T02:06:11.695000+00:00


SOURCES UPDATE DATE

db:BIDid:31331date:2008-09-24T18:09:00

SOURCES RELEASE DATE

db:BIDid:31331date:2008-09-22T00:00:00