CVE-2008-6280
Cisco WRT160N - Cross-Site Scripting via DHCP_Static Action Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-6280. PoCs published by David Gil.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in Linksys WRT160N by crafting a malicious URI that injects arbitrary JavaScript code into the 'apply.cgi' endpoint. The payload triggers an alert dialog, proving the lack of input sanitization.
Description
Cross-site scripting (XSS) vulnerability in apply.cgi on the Linksys WRT160N allows remote attackers to inject arbitrary web script or HTML via the action parameter in a DHCP_Static operation.
Exploits (1)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in Linksys WRT160N by crafting a malicious URI that injects arbitrary JavaScript code into the 'apply.cgi' endpoint. The payload triggers an alert dialog, proving the lack of input sanitization.