Vulnerabilities > CVE-2007-4318 - Cross-Site Scripting vulnerability in Zyxel Zynos and Zywall 2

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
zyxel
exploit available

Summary

Cross-site scripting (XSS) vulnerability in Forms/General_1 in the management interface in ZyNOS firmware 3.62(WK.6) on the Zyxel Zywall 2 device allows remote authenticated administrators to inject arbitrary web script or HTML via the sysSystemName parameter.

Vulnerable Configurations

Part Description Count
Hardware
Zyxel
2

Exploit-Db

descriptionZyXEL ZyWALL 2 3.62 Forms/General_1 sysSystemName Parameter XSS. CVE-2007-4318. Remote exploit for hardware platform
idEDB-ID:30485
last seen2016-02-03
modified2007-08-10
published2007-08-10
reporterHenri Lindberg
sourcehttps://www.exploit-db.com/download/30485/
titleZyXEL ZyWALL 2 3.62 Forms/General_1 sysSystemName Parameter XSS