CVE-2008-1253

D-Link DSL-G604T - XSS

Title source: llm

Description

Cross-site scripting (XSS) vulnerability in cgi-bin/webcm on the D-Link DSL-G604T router allows remote attackers to inject arbitrary web script or HTML via the var:category parameter, as demonstrated by a request for advanced/portforw.htm on the fwan page.

Scores

EPSS 0.0021
EPSS Percentile 43.0%

Classification

CWE
CWE-79
Status draft

Affected Products (1)

d-link/dsl-g604t

Timeline

Published Mar 10, 2008
Tracked Since Feb 18, 2026