Page 4 of 16 results (0.006 seconds)

CVSS: 6.1EPSS: 0%CPEs: 2EXPL: 1

Cross-site scripting in notice_gen.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to execute arbitrary JavaScript by modifying the "User phrases button" field. Cross-Site Scripting (XSS), en notice_gen.htm en la versión 1.0.8 de TOTOLINK A3002RU, permite a los atacantes remotos ejecutar código arbitrario de JavaScript, modificando el campo "User phrases button". • https://blog.securityevaluators.com/new-vulnerabilities-in-totolink-a3002ru-d6f42a081154 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •