38721vdb entry
http://osvdb.org/38721 CVE-2007-4318
ZYXEL ZyWALL 2 3.62 - '/Forms/General_1?sysSystemName' Cross-Site Scripting
Record summary
CVE-2007-4318 has a selected CVSS score of 4.3; EIP currently links 1 catalogued exploit.
Description
Cross-site scripting (XSS) vulnerability in Forms/General_1 in the management interface in ZyNOS firmware 3.62(WK.6) on the Zyxel Zywall 2 device allows remote authenticated administrators to inject arbitrary web script or HTML via the sysSystemName parameter.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBZYXEL ZyWALL 2 3.62 - '/Forms/General_1?sysSystemName' Cross-Site ScriptingExploitDB exploitby Henri LindbergNot analyzed1 file
References
826381Third-party advisory
http://secunia.com/advisories/26381 3002Third-party advisory
http://securityreason.com/securityalert/3002 louhi.fi
http://www.louhi.fi/advisory/zyxel_070810.txt 20070810 Zyxel Zywall 2 multiple vulnerabilitiesmailing list
http://www.securityfocus.com/archive/1/476031/100/0/threaded 25262vdb entry
http://www.securityfocus.com/bid/25262 zywall-management-csrf(35913)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/35913 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2007-4318