Page 5 of 42 results (0.002 seconds)

CVSS: 6.1EPSS: 0%CPEs: 2EXPL: 1

26 Nov 2018 — Cross-site scripting in notice_gen.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to execute arbitrary JavaScript by modifying the "User phrases button" field. Cross-Site Scripting (XSS), en notice_gen.htm en la versión 1.0.8 de TOTOLINK A3002RU, permite a los atacantes remotos ejecutar código arbitrario de JavaScript, modificando el campo "User phrases button". • https://blog.securityevaluators.com/new-vulnerabilities-in-totolink-a3002ru-d6f42a081154 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.1EPSS: 0%CPEs: 2EXPL: 1

26 Nov 2018 — Cross-site scripting in notice_gen.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to execute arbitrary JavaScript by modifying the "Input your notice URL" field. Cross-Site Scripting (XSS), en notice_gen.htm en la versión 1.0.8 de TOTOLINK A3002RU, permite a los atacantes remotos ejecutar código arbitrario de JavaScript, modificando el campo "Input your notice URL" . • https://blog.securityevaluators.com/new-vulnerabilities-in-totolink-a3002ru-d6f42a081154 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •