ID
VAR-201101-0409
TITLE
Linksys BEFSR41 Storage Cross-Site Scripting Vulnerability
Trust: 0.6
DESCRIPTION
Linksys BEFSR41 is a Linksys high-speed Cable/DSL switching router. Linksys does not verify the input size and can cause stored cross-site scripting errors. Hostname, username (PPPoE and PPTP), customizable applications and other fields are affected by this vulnerability. Linksys BEFSR41 is prone to multiple HTML-injection vulnerabilities because it fails to sufficiently sanitize user-supplied input data. Exploiting these issues may allow an attacker to execute HTML and script code in the context of the device, to steal cookie-based authentication credentials, or to control how the site is rendered to the user; other attacks are also possible
Trust: 1.35
IOT TAXONOMY
category: | ['Network device'] | sub_category: | - | Trust: 1.2 |
AFFECTED PRODUCTS
vendor: | linksys | model: | bef sr41 | scope: | - | version: | - | Trust: 1.2 |
vendor: | linksys | model: | befsr41 | scope: | eq | version: | 0 | Trust: 0.3 |
THREAT TYPE
network
Trust: 0.3
TYPE
Input Validation Error
Trust: 0.3
EXTERNAL IDS
db: | BID | id: | 45658 | Trust: 1.5 |
db: | CNVD | id: | CNVD-2011-0011 | Trust: 0.6 |
db: | CNVD | id: | CNVD-2011-0012 | Trust: 0.6 |
REFERENCES
url: | http://www.securityfocus.com/archive/1/515532 | Trust: 1.2 |
url: | http://www.linksys.com | Trust: 0.3 |
url: | /archive/1/515532 | Trust: 0.3 |
CREDITS
DcLabs Security Group
Trust: 0.3
SOURCES
db: | CNVD | id: | CNVD-2011-0011 |
db: | CNVD | id: | CNVD-2011-0012 |
db: | BID | id: | 45658 |
LAST UPDATE DATE
2022-05-17T02:10:00.068000+00:00
SOURCES UPDATE DATE
db: | CNVD | id: | CNVD-2011-0011 | date: | 2011-01-05T00:00:00 |
db: | CNVD | id: | CNVD-2011-0012 | date: | 2011-01-05T00:00:00 |
db: | BID | id: | 45658 | date: | 2011-01-04T00:00:00 |
SOURCES RELEASE DATE
db: | CNVD | id: | CNVD-2011-0011 | date: | 2011-01-05T00:00:00 |
db: | CNVD | id: | CNVD-2011-0012 | date: | 2011-01-05T00:00:00 |
db: | BID | id: | 45658 | date: | 2011-01-04T00:00:00 |