O2 classic router: persistent cross site scripting (XSS) and cross site request forgery (CSRF)

0
82

Posted by Hanno Böck on Apr 07

O2 classic router: persistent cross site scripting (XSS) and cross site
request forgery (CSRF)

References

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1482
http://int21.de/cve/CVE-2011-0746-o2-router.html

Description

The default DSL router shipped by the german company O2 is completely
vulnerable to persistent cross site scripting (XSS) and cross site
request forgery (CSRF). The device is produced by ZyXEL, it seems it
has no other…

Source: O2 classic router: persistent cross site scripting (XSS) and cross site request forgery (CSRF)