CVE Feed

    Dashboard / CVE / CVE-2013-6786

    CVE-2013-6786

    Cross-site scripting (XSS) vulnerability in Allegro RomPager before 4.51, as used on the ZyXEL P660HW-D1, Huawei MT882, Sitecom WL-174, TP-LINK TD-8816, and D-Link DSL-2640R and DSL-2641R, when the "forbidden author header" protection mechanism is bypassed, allows remote attackers to inject arbitrary web script or HTML by requesting a nonexistent URI in conjunction with a crafted HTTP Referer header that is not properly handled in a 404 page. NOTE: there is no CVE for a "URL redirection" issue that some sources list separately.

    Published:Jan 16, 2014
    Last Modified:Apr 11, 2025
    EPS:Jan 16, 2014
    EPSS Score:0.00269
    CVSS Score:4.3

    Affected Products

    Vendor
    Allegrosoft
    Product
    Rompager
    Vendor
    Dlink
    Product
    Dsl-2640r
    Vendor
    Dlink
    Product
    Dsl-2641r
    Vendor
    Huawei
    Product
    Mt882
    Vendor
    Sitecom
    Product
    Wl-174
    Vendor
    Tp-link
    Product
    Td-8816
    Vendor
    Zyxel
    Product
    P-660hw D1

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High