Netgear FVS318 Router Multiple... CVE-2005-0291 CNVD-2005-0241 CNNVD-200501-252

4.3 AV AC AU C I A
发布: 2005-01-17
修订: 2017-07-11

Multiple Vulnerabilities in Netgear FVS318 Router ------------------------------------------------------------------------ SUMMARY The <http://www.netgear.com> Netgear FVS318 is "an easy to use, firewall/router designed for home users and small businesses". SecuriNews Research has found 2 vulnerabilities in the router, one allows bypassing the product's content filtering mechanism while the other allows injecting arbitrary HTML and/or JavaScript into the product's log files which can then be used to attack the administrator of the router. DETAILS Content Filtering Bypass: By using HEX encoded characters, it is possible to bypass the URL filter. For example, if the router administrator blocks the phrase ".exe"; a user can encode one or more characters in the URL phrase to bypass the filter. If we encode the 'x' in ".exe", the new phrase ".e%78e" will bypass the filter. Log File Arbitrary Content Injection: The content filter/log viewer contains a Cross Site Scripting vulnerability....

0%
暂无可用Exp或PoC
当前有1条受影响产品信息