Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-2167. PoCs published by Deniz Cevik.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in ZyWALL 100 by injecting a malicious script via the Referer header. The PoC shows how arbitrary JavaScript can be executed in the context of the affected site.
Description
Cross-site scripting (XSS) vulnerability in ZyXEL ZyWALL 100 allows remote attackers to inject arbitrary web script or HTML via the Referer header, which is not properly handled in a 404 Error page.
Exploits (1)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in ZyWALL 100 by injecting a malicious script via the Referer header. The PoC shows how arbitrary JavaScript can be executed in the context of the affected site.