4.3
CVSSv2

CVE-2010-0936

Published: 08/03/2010 Updated: 17/08/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 440
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in auth.asp on the D-LINK DKVM-IP8 with firmware 2282_dlinkA4_p8_20071213 allows remote malicious users to inject arbitrary web script or HTML via the nickname parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

d-link dkvm-ip8 2282_dlinka4_p8_20071213

Exploits

source: wwwsecurityfocuscom/bid/37646/info D-LINK DKVM-IP8 is prone to a cross-site scripting vulnerability because the device's web interface fails to properly sanitize user-supplied input An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site Thi ...
# Exploit Title: D-LINK DKVM-IP8 XSS Vulnerability # Date: 01-06-2010 # Author: POPCORN # Software Link: wwwdlinkru/ # Version: 2282_dlinkA4_p8_20071213 # Tested on: Windows Sp 2 # Site : Hackingge # Code : POST sitecom80/authasp HTTP/10 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/40 ( ...