Release date:
Updated on:
Affected Systems:
D-Link DIR-615
D-Link DIR-300
Description:
--------------------------------------------------------------------------------
DIR-300 and DIR-615 are wireless router products.
The validity of parameters passed by the DIR-300 and DIR-615 to the tools_log_setting.php for the "send_mail" GET parameter is not properly filtered, and arbitrary HTML and script code can be executed in the affected site user browser session.
<* Source: Michael Messner (michae.messner@integralis.com)
Link: http://secunia.com/advisories/53161/
Http://www.s3cur1ty.de/m1adv2013-014
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
D-Link
------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.dlink.com/