CVE-2007-3574

Linksys Wag54gs - XSS

Title source: rule

Description

Multiple cross-site scripting (XSS) vulnerabilities in setup.cgi on the Cisco Linksys WAG54GS Wireless-G ADSL Gateway with 1.00.06 firmware allow remote attackers to inject arbitrary web script or HTML via the (1) c4_trap_ip_, (2) devname, (3) snmp_getcomm, or (4) snmp_setcomm parameter.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Petko Petkov · textremotehardware
https://www.exploit-db.com/exploits/30254

Scores

EPSS 0.0883
EPSS Percentile 92.4%

Classification

CWE
CWE-79
Status draft

Affected Products (1)

linksys/wag54gs

Timeline

Published Jul 05, 2007
Tracked Since Feb 18, 2026