CVE-2008-1257
Published Mar 10, 2008
Last updated 6 years ago
Overview
- Description
- Cross-site scripting (XSS) vulnerability in Forms/DiagGeneral_2 on the ZyXEL P-660HW series router allows remote attackers to inject arbitrary web script or HTML via the PingIPAddr parameter.
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 4.3
- Impact score
- 2.9
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:N/I:P/A:N
Weaknesses
- nvd@nist.gov
- CWE-79
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:zyxel:p-660hw:_t1:-:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FF56F788-1143-4B88-826D-27B7AF8E629B" }, { "criteria": "cpe:2.3:h:zyxel:p-660hw:_t1:v2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "918195BD-67A3-4AC2-9426-F7F77EAAA4CF" }, { "criteria": "cpe:2.3:h:zyxel:p-660hw_d1:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1D13FB1A-637D-4E69-B84F-05531DCA5769" }, { "criteria": "cpe:2.3:h:zyxel:p-660hw_d1:v2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8345A967-7E5B-4E09-B21A-A722FC249102" }, { "criteria": "cpe:2.3:h:zyxel:p-660hw_d3:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "465FD6ED-C294-49B2-8F2C-8EF0633DABFF" }, { "criteria": "cpe:2.3:h:zyxel:p-660hw_t3:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "26E8D38B-1859-4DCE-A566-777432CB7E9D" }, { "criteria": "cpe:2.3:h:zyxel:p-660hw_t3:v2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4BC3F2BD-2E86-4EC3-A837-E9B862E74193" } ], "operator": "OR" } ] } ]