ID
VAR-201005-0434
TITLE
U.S.Robotics USR5463 firmware 'setup_ddns.exe' HTML injection vulnerability
Trust: 0.9
DESCRIPTION
U.S.Robotics USR5463 is a popular router device in foreign countries. The 'setup_ddns.exe' script included in USRobotics USR5463 firmware does not handle user input correctly. Remote attackers can exploit vulnerabilities for cross-site scripting attacks. After enticing the target users to view, they can obtain sensitive information such as COOKIE and hijack the target user session. U.S.Robotics USR5463 firmware is prone to an HTML-injection vulnerability because it fails to sufficiently sanitize user-supplied data. Attacker-supplied HTML or JavaScript code could run in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials and to control how the site is rendered to the user; other attacks are also possible. U.S.Robotics firmware USR5463 0.06 is vulnerable
Trust: 0.81
IOT TAXONOMY
category: | ['Network device'] | sub_category: | - | Trust: 0.6 |
AFFECTED PRODUCTS
vendor: | u s robotics | model: | usr5463 | scope: | eq | version: | 0.06 | Trust: 0.9 |
THREAT TYPE
network
Trust: 0.3
TYPE
Input Validation Error
Trust: 0.3
EXTERNAL IDS
db: | BID | id: | 40292 | Trust: 0.9 |
db: | CNVD | id: | CNVD-2010-0926 | Trust: 0.6 |
REFERENCES
url: | http://www.securityfocus.com/archive/1/511370 | Trust: 0.6 |
url: | http://www.usr-emea.com/support/s-prod-template.asp?loc=emea&prod=5463 | Trust: 0.3 |
url: | /archive/1/511370 | Trust: 0.3 |
CREDITS
SH4V
Trust: 0.3
SOURCES
db: | CNVD | id: | CNVD-2010-0926 |
db: | BID | id: | 40292 |
LAST UPDATE DATE
2022-05-17T01:38:06.565000+00:00
SOURCES UPDATE DATE
db: | CNVD | id: | CNVD-2010-0926 | date: | 2010-05-21T00:00:00 |
db: | BID | id: | 40292 | date: | 2010-05-20T00:00:00 |
SOURCES RELEASE DATE
db: | CNVD | id: | CNVD-2010-0926 | date: | 2010-05-21T00:00:00 |
db: | BID | id: | 40292 | date: | 2010-05-20T00:00:00 |