Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2013-7389

Severity
4.3MEDIUM
EPSS
92.2%
top 0.28%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedJul 7
Latest updateMay 17

Description

Multiple cross-site scripting (XSS) vulnerabilities in D-Link DIR-645 Router (Rev. A1) with firmware before 1.04B11 allow remote attackers to inject arbitrary web script or HTML via the (1) deviceid parameter to parentalcontrols/bind.php, (2) RESULT parameter to info.php, or (3) receiver parameter to bsc_sms_send.php.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages2 packages

Patches

🔴Vulnerability Details

3
GHSA
GHSA-w84x-2hxj-9gfv: Multiple cross-site scripting (XSS) vulnerabilities in D-Link DIR-645 Router (Rev2022-05-17
CVEList
CVE-2013-7389: Multiple cross-site scripting (XSS) vulnerabilities in D-Link DIR-645 Router (Rev2014-07-07
VulnCheck
D-Link DIR-645 Router Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2013

💥Exploits & PoCs

1
Exploit-DB
D-Link DIR-645 1.03B08 - Multiple Vulnerabilities2013-08-02
CVE-2013-7389 (MEDIUM CVSS 4.3) | Multiple cross-site scripting (XSS) | cvebase.io