Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2018-6527


XSS vulnerability in htdocs/webinc/js/adv_parent_ctrl_map.php in D-Link DIR-868L DIR868LA1_FW112b04 and previous versions, DIR-865L DIR-865L_REVA_FIRMWARE_PATCH_1.08.B01 and previous versions, and DIR-860L DIR860LA1_FW110b04 and previous versions allows remote attackers to read a cookie via a crafted deviceid parameter to soap.cgi.


Published

2018-03-06T20:29:00.780

Last Modified

2024-11-21T04:10:50.220

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.1 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:N/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

8.6

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System dlink dir-860l_firmware ≤ a1_fw110b04 Yes
Hardware dlink dir-860l - No
Operating System dlink dir-865l_firmware ≤ reva_firmware_patch_1.08.b01 Yes
Hardware dlink dir-865l - No
Operating System dlink dir-868l_firmware ≤ a1_fw112b04 Yes
Hardware dlink dir-868l - No

References