Vulnerabilities > CVE-2006-0946 - Cross-Site Scripting vulnerability in Thomson SpeedTouch 500 Series

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
thomson
exploit available

Summary

Cross-site scripting (XSS) vulnerability in Thomson SpeedTouch modems running firmware 5.3.2.6.0 allows remote attackers to inject arbitrary web script or HTML via the name parameter to the LocalNetwork page.

Exploit-Db

descriptionThomson SpeedTouch 500 Series LocalNetwork Page name Parameter XSS. CVE-2006-0946. Remote exploit for hardware platform
idEDB-ID:27320
last seen2016-02-03
modified2006-02-25
published2006-02-25
reporterPreben Nylokken
sourcehttps://www.exploit-db.com/download/27320/
titleThomson SpeedTouch 500 Series LocalNetwork Page name Parameter XSS