CVE-2014-7857
https://notcve.org/view.php?id=CVE-2014-7857
D-Link DNS-320L firmware before 1.04b12, DNS-327L before 1.03b04 Build0119, DNR-326 1.40b03, DNS-320B 1.02b01, DNS-345 1.03b06, DNS-325 1.05b03, and DNS-322L 2.00b07 allow remote attackers to bypass authentication and log in with administrator permissions by passing the cgi_set_wto command in the cmd parameter, and setting the spawned session's cookie to username=admin. DNS-320L firmware anterior a la versión 1.04b12, DNS-327L anterior a la versión 1.03b04 Build0119, DNR-326 versión 1.40b03, DNS-320B versión 1.02b01, DNS-345 versión 1.03b06, DNS-325 versión 1.05b03, y DNS-322L versión 2.00b07 de D-Link, permite a los atacantes remotos omitir la autenticación e iniciar sesión con los permisos de administrador omitiendo el comando cgi_set_wto en el parámetro cmd y ajustando la cookie de sesión creada en username=admin. • http://packetstormsecurity.com/files/132075/D-Link-Bypass-Buffer-Overflow.html http://seclists.org/fulldisclosure/2015/May/125 http://www.search-lab.hu/media/D-Link_Security_advisory_3_0_public.pdf http://www.securityfocus.com/archive/1/535626/100/200/threaded http://www.securityfocus.com/bid/74880 • CWE-287: Improper Authentication •
CVE-2014-9518
https://notcve.org/view.php?id=CVE-2014-9518
Cross-site scripting (XSS) vulnerability in login.cgi in D-Link router DIR-655 (rev Bx) with firmware before 2.12b01 allows remote attackers to inject arbitrary web script or HTML via the html_response_page parameter. Vulnerabilidad de XSS en login.cgi en D-Link router DIR-655 (rev Bx) con firmware anterior a 2.12b01 permite a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarios a través del parámetro html_response_page. • http://secunia.com/advisories/61831 http://securityadvisories.dlink.com/security/publication.aspx?name=SAP10048 http://www.securityfocus.com/bid/71772 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2014-9238
https://notcve.org/view.php?id=CVE-2014-9238
D-link IP camera DCS-2103 with firmware 1.0.0 allows remote attackers to obtain the installation path via the file parameter to cgi-bin/sddownload.cgi, as demonstrated by a / (forward slash) character. D-link IP camera DCS-2103 con firmware 1.0.0 permite a atacantes remotos obtener la ruta de instalación a través del parámetro file en cgi-bin/sddownload.cgi, tal y como fue demostrado por un caracter / (barra oblicua). • http://packetstormsecurity.com/files/129138/D-Link-DCS-2103-Directory-Traversal.html http://seclists.org/fulldisclosure/2014/Nov/42 http://websecurity.com.ua/7250 http://www.securityfocus.com/bid/71484 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •
CVE-2014-9234
https://notcve.org/view.php?id=CVE-2014-9234
Directory traversal vulnerability in cgi-bin/sddownload.cgi in D-link IP camera DCS-2103 with firmware 1.0.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter. Vulnerabilidad de salto de directorio en cgi-bin/sddownload.cgi en D-link IP camera DCS-2103 con firmware 1.0.0 permite a atacantes remotos leer ficheros arbitrarios a través de un .. (punto punto) en el parámetro file. • http://packetstormsecurity.com/files/129138/D-Link-DCS-2103-Directory-Traversal.html http://seclists.org/fulldisclosure/2014/Nov/42 http://websecurity.com.ua/7250 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •
CVE-2013-7321
https://notcve.org/view.php?id=CVE-2013-7321
Cross-site scripting (XSS) vulnerability in D-Link DAP-2253 Access Point (Rev. A1) with firmware before 1.30 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. Vulnerabilidad de XSS en el punto de acceso D-Link DAP-2253 (Rev. A1) con firmware anterior a 1.30 permite a atacantes remotos inyectar script Web o HTML arbitrario a través de vectores no especificados. • http://secunia.com/advisories/56022 http://securityadvisories.dlink.com/security/publication.aspx?name=SAP10006 http://www.securityfocus.com/bid/64297 https://exchange.xforce.ibmcloud.com/vulnerabilities/89728 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •