vendor:
Linksys Wireless-G ADSL Gateway
by:
Unknown
7.5
CVSS
HIGH
Cross-Site Scripting
79
CWE
Product Name: Linksys Wireless-G ADSL Gateway
Affected Version From: Linksys Wireless-G ADSL Gateway WAG54GS running firmware V1.00.06
Affected Version To: Unknown
Patch Exists: NO
Related CWE:
CPE: h:cisco:linksys_wag54gs_firmware:v1.00.06
Platforms Tested:
Unknown
Cross-Site Scripting Vulnerabilities in Linksys Wireless-G ADSL Gateway
The Linksys Wireless-G ADSL Gateway is prone to multiple cross-site scripting vulnerabilities due to inadequate input sanitization. Attackers can exploit this by enticing victims to open a malicious URI. This can lead to the execution of arbitrary script code in the user's browser within the context of the affected device. The attacker can then steal authentication credentials, cause denial-of-service conditions, and launch further attacks. Successful exploits allow persistent storage of script code in the affected device.
Mitigation:
There is no specific mitigation information available for this vulnerability.