CVE-2008-1243

Linksys WRT300N 2.00.20 - Cross-Site Scripting via dyndns_domain Parameter

Title source: llm
STIX 2.1

Description

Cross-site scripting (XSS) vulnerability on the Linksys WRT300N router with firmware 2.00.20, when Mozilla Firefox or Apple Safari is used, allows remote attackers to inject arbitrary web script or HTML via the dyndns_domain parameter to the default URI.

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/489009/100/0/threaded
Exploit x_refsource_misc
http://code.bulix.org/cx46qa-65489
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/41121
Exploit x_refsource_misc
http://code.bulix.org/koom78-65490

Scores

EPSS 0.0034
EPSS Percentile 56.8%

Details

CWE
CWE-79
Status published
Products (1)
linksys/wrt300n
Published Mar 10, 2008
Tracked Since Feb 18, 2026