A reflected cross-site-scripting attack in web application of D-Link DIR-X1860 before v1.10WWB09_Beta allows a remote unauthenticated attacker to execute code in the device of the victim via sending a specific URL to the unauthenticated victim.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
http://d-link.com | broken link |
https://www.dlink.com/en/security-bulletin/ | vendor advisory |
http://dir-x1860.com | broken link url repurposed |
https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10283 | patch vendor advisory |