Cross-site scripting (XSS) vulnerability in cgi-bin/webcm on the D-Link DSL-G604T router allows remote malicious users to inject arbitrary web script or HTML via the var:category parameter, as demonstrated by a request for advanced/portforw.htm on the fwan page.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
d-link dsl-g604t |