« Volver al listado

CVE-2013-6786

Estado: ModificadaMedia (4.3)—

Cross-site scripting (XSS) vulnerability in Allegro RomPager before 4.51, as used on the ZyXEL P660HW-D1, Huawei MT882, Sitecom WL-174, TP-LINK TD-8816, and D-Link DSL-2640R and DSL-2641R, when the "forbidden author header" protection mechanism is bypassed, allows remote attackers to inject arbitrary web script or HTML by requesting a nonexistent URI in conjunction with a crafted HTTP Referer header that is not properly handled in a 404 page. NOTE: there is no CVE for a "URL redirection" issue that some sources list separately.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (7)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2013-6786",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2014-01-16T19:55:04.607",
  "references": [
    {
      "url": "http://antoniovazquezblanco.github.io/docs/advisories/Advisory_RomPagerXSS.pdf",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://osvdb.org/99694",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://osvdb.org/ref/99/rompager407.pdf",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://antoniovazquezblanco.github.io/docs/advisories/Advisory_RomPagerXSS.pdf",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://osvdb.org/99694",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://osvdb.org/ref/99/rompager407.pdf",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Cross-site scripting (XSS) vulnerability in Allegro RomPager before 4.51, as used on the ZyXEL P660HW-D1, Huawei MT882, Sitecom WL-174, TP-LINK TD-8816, and D-Link DSL-2640R and DSL-2641R, when the \"forbidden author header\" protection mechanism is bypassed, allows remote attackers to inject arbitrary web script or HTML by requesting a nonexistent URI in conjunction with a crafted HTTP Referer header that is not properly handled in a 404 page.  NOTE: there is no CVE for a \"URL redirection\" issue that some sources list separately."
    },
    {
      "lang": "es",
      "value": "Vulnerabilidad de XSS en Allegro RomPager anterior a la versión 4.51, tal y como se usa en ZyXEL P660HW-D1, Huawei MT882, Sitecom WL-174, TP-LINK TD-8816, y D-Link DSL-2640R y DSL-2641R, cuando los mecanismos de protección \"forbidden author header\" son evadidos, permite a atacantes remotos inyectar script Web o HTML arbitrario mediante la petición de una URI no existente en conjunción con una cabecera HTTP Referer manipulada que no es manejada adecuadamente en una página 404. NOTA: no hay CVE para una \"redirección de URL\", que algunas fuentes enumeran por separado."
    }
  ],
  "lastModified": "2026-06-17T00:00:56.043",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:allegrosoft:rompager:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FDBB61DF-D173-4046-B619-C762147742A8",
              "versionEndIncluding": "4.07"
            },
            {
              "criteria": "cpe:2.3:h:dlink:dsl-2640r:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3F29B74A-18E6-45AD-BACD-27AA2777DB70"
            },
            {
              "criteria": "cpe:2.3:h:dlink:dsl-2641r:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "62B6395E-1FEF-4F66-9B50-8E9038AD469A"
            },
            {
              "criteria": "cpe:2.3:h:huawei:mt882:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0527EC70-2D03-4BEB-A1CB-F34DC1AB1BE8"
            },
            {
              "criteria": "cpe:2.3:h:sitecom:wl-174:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "85367E17-94F4-49B2-80D9-977AF0C52CD6"
            },
            {
              "criteria": "cpe:2.3:h:tp-link:td-8816:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BE41D744-06A9-4522-B409-414E11483DD3"
            },
            {
              "criteria": "cpe:2.3:h:zyxel:p-660hw_d1:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1D13FB1A-637D-4E69-B84F-05531DCA5769"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}