CVE-2021-46387 – Zyxel ZyWALL 2 Plus Internet Security Appliance - Cross-Site Scripting (XSS)
https://notcve.org/view.php?id=CVE-2021-46387
ZyXEL ZyWALL 2 Plus Internet Security Appliance is affected by Cross Site Scripting (XSS). Insecure URI handling leads to bypass security restriction to achieve Cross Site Scripting, which allows an attacker able to execute arbitrary JavaScript codes to perform multiple attacks such as clipboard hijacking and session hijacking. ZyXEL ZyWALL 2 Plus Internet Security Appliance está afectado por una vulnerabilidad de tipo Cross Site Scripting (XSS). Un manejo no seguro de URI conlleva a omitir la restricción de seguridad para lograr una vulnerabilidad de tipo Cross Site Scripting, lo que permite a un atacante capaz de ejecutar códigos JavaScript arbitrarios para llevar a cabo múltiples ataques como el secuestro del portapapeles y el secuestro de la sesión. Zyxel ZyWALL 2 Plus suffers from a cross site scripting vulnerability. • https://www.exploit-db.com/exploits/50797 http://packetstormsecurity.com/files/166189/Zyxel-ZyWALL-2-Plus-Cross-Site-Scripting.html https://drive.google.com/drive/folders/1_XfWBLqxT2Mqt7uB663Sjlc62pE8-rcN?usp=sharing https://www.zyxel.com/uk/en/products_services/zywall_2_plus.shtml https://www.zyxel.com/us/en/support/security_advisories.shtml • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •