CVE-2004-0615
published 2004-12-06CVE-2004-0615: Cross-site scripting (XSS) vulnerability in D-Link DI-614+ SOHO router running firmware 2.30, and DI-704 SOHO router running firmware 2.60B2, and DI-624…
PriorityP420medium5.1CVSS 2.0
AVNACHAuNCPIPAP
EXPLOIT
EPSS
2.43%
82.4th percentile
Cross-site scripting (XSS) vulnerability in D-Link DI-614+ SOHO router running firmware 2.30, and DI-704 SOHO router running firmware 2.60B2, and DI-624, allows remote attackers to inject arbitrary script or HTML via the DHCP HOSTNAME option in a DHCP request.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| d-link | di-614 | — | — |
| d-link | di-704p | — | — |
| dlink | di-624 | <= 1.28 | — |
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Exploit-DB
D-Link AirPlus DI-614+ / DI-624 / DI-704 - DHCP Log HTML Injection
exploitdb·2004-06-21
CVE-2004-0615 D-Link AirPlus DI-614+ / DI-624 / DI-704 - DHCP Log HTML Injection
D-Link AirPlus DI-614+ / DI-624 / DI-704 - DHCP Log HTML Injection
---
source: https://www.securityfocus.com/bid/10587/info
It is reported that the DI-614+, DI-704, and the DI-624 are susceptible to an HTML injection vulnerability in their DHCP log.
An attacker who has access to the wireless, or internal network segments of the router can craft malicious DHCP hostnames, that when sent to the router, will be logged for later viewing by the administrator of the device.
The injected HTML can be used to cause the administrator to make unintended changes to the configuration of the router. Other attacks may be possible.
Although only the DI-614+, DI-704, and the DI-624 are reported vulnerable, code reuse across devices is common and other products may also be affected.
By sending four re
Exploit-DB
e107 website system 0.6 - 'usersettings.php?avmsg' Cross-Site Scripting
exploitdb·2004-05-29
CVE-2004-2040 e107 website system 0.6 - 'usersettings.php?avmsg' Cross-Site Scripting
e107 website system 0.6 - 'usersettings.php?avmsg' Cross-Site Scripting
---
source: https://www.securityfocus.com/bid/10436/info
e107 is prone to multiple cross-site scripting, HTML injection, file inclusion, and SQL injection vulnerabilities. This may compromise various security properties of a Web site running the software, including allowing remote attackers to execute malicious PHP code.
http://www.example.com/e107_0615/usersettings.php?avmsg=[xss code here]
No writeups or analysis indexed.
http://archives.neohapsis.com/archives/bugtraq/2004-07/0014.htmlhttp://marc.info/?l=bugtraq&m=108786257609932&w=2http://marc.info/?l=bugtraq&m=108797273127182&w=2http://secunia.com/advisories/11919http://securitytracker.com/id?1010562http://www.osvdb.org/7211http://www.securityfocus.com/bid/10587https://exchange.xforce.ibmcloud.com/vulnerabilities/16468http://archives.neohapsis.com/archives/bugtraq/2004-07/0014.htmlhttp://marc.info/?l=bugtraq&m=108786257609932&w=2http://marc.info/?l=bugtraq&m=108797273127182&w=2http://secunia.com/advisories/11919http://securitytracker.com/id?1010562http://www.osvdb.org/7211http://www.securityfocus.com/bid/10587https://exchange.xforce.ibmcloud.com/vulnerabilities/16468
2004-12-06
Published