CVE-2013-3065 - Cross-Site Scripting (XSS) vulnerability in Linksys Ea6500 and Ea6500 Firmware

Publication

2014-09-29

Last modification

2014-09-30

Summary

Cross-site scripting (XSS) vulnerability in the Parental Controls section in Linksys EA6500 with firmware 1.1.28.147876 allows remote authenticated users to inject arbitrary web script or HTML via vectors related to the Blocked Specific Sites section.

Classification

CWE-79 - Cross-Site Scripting (XSS)

Risk level (CVSS AV:N/AC:M/Au:S/C:N/I:P/A:N)

Low

3.5

Access Vector

  • Network
  • Adjacent Network
  • Local

Access Complexity

  • Low
  • Medium
  • High

Authentication

  • None
  • Single
  • Multiple

Confident. Impact

  • Complete
  • Partial
  • None

Integrity Impact

  • Complete
  • Partial
  • None

Affected Products

Vendor Product Versions
Linksys Ea6500 
Linksys Ea6500 Firmware  1.1.28.147876