CVE-2013-6786
Cross-site scripting (XSS) vulnerability in Allegro RomPager before 4.51, as used on the ZyXEL P660HW-D1, Huawei MT882, Sitecom WL-174, TP-LINK TD-8816, and D-Link DSL-2640R and DSL-2641R, when the "forbidden author header" protection mechanism is bypassed, allows remote attackers to inject arbitrary web script or HTML by requesting a nonexistent URI in conjunction with a crafted HTTP Referer header that is not properly handled in a 404 page. NOTE: there is no CVE for a "URL redirection" issue that some sources list separately.
Published:Jan 16, 2014
Last Modified:Apr 11, 2025
EPS:Jan 16, 2014
EPSS Score:0.00269
CVSS Score:4.3
Affected Products
Vendor
Product
Action
Vendor
Allegrosoft
Product
Rompager
Allegrosoft
Rompager
Vendor
Dlink
Product
Dsl-2640r
Dlink
Dsl-2640r
Vendor
Dlink
Product
Dsl-2641r
Dlink
Dsl-2641r
Vendor
Huawei
Product
Mt882
Huawei
Mt882
Vendor
Sitecom
Product
Wl-174
Sitecom
Wl-174
Vendor
Tp-link
Product
Td-8816
Tp-link
Td-8816
Vendor
Zyxel
Product
P-660hw D1
Zyxel
P-660hw D1
Exploits
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
