435
VMScore

CVE-2019-10677

Published: 05/09/2019 Updated: 09/09/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple Cross-Site Scripting (XSS) issues in the web interface on DASAN Zhone ZNID GPON 2426A EU version S3.1.285 devices allow a remote malicious user to execute arbitrary JavaScript via manipulation of an unsanitized GET parameter: /zhndnsdisplay.cmd (name), /wlsecrefresh.wl (wlWscCfgMethod, wl_wsc_reg).

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

dasanzhone znid_gpon_2426a_eu_firmware

Exploits

Multiple Cross-Site Scripting (XSS) in the web interface of DASAN Zhone ZNID GPON 2426A EU version S31285 application allows a remote attacker to execute arbitrary JavaScript via manipulation of an unsanitized GET parameters # Exploit Title: Multiple Cross-Site Scripting (XSS) in DASAN Zhone ZNID GPON 2426A EU # Date: 31032019 # Exploit Aut ...
DASAN Zhone ZNID GPON 2426A EU versions S31285 and below suffer from multiple cross site scripting vulnerabilities ...