vendor:
DIR-615
by:
Osanda Malith Jayathissa
8,8
CVSS
HIGH
Open Redirection and XSS
601 (Open Redirection) and 79 (XSS)
CWE
Product Name: DIR-615
Affected Version From: 5.10
Affected Version To: 5.10
Patch Exists: YES
Related CWE: None
CPE: h:d-link:dir-615
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 8 64-bit
2017
D-Link DIR-615 Multiple Vulnerabilities
The 'apply.cgi' file was vulnerable to Open Redirection and XSS. Inside the router many other cgi files too use this functionality in 'apply.cgi'. For example the 'ping_response.cgi' file. The exploit code for Open Redirection and XSS is provided in the text.
Mitigation:
Ensure that user input is validated and sanitized before being used in the application. Also, ensure that the application is running the latest version of the software.