NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
1216 | CVE-2008-1257 | Cross-site scripting (XSS) vulnerability in Forms/DiagGeneral_2 on the ZyXEL P-660HW series router allows remote attackers to inject arbitrary web script or HTML via the PingIPAddr parameter. | 2 | 4.3 | Medium | 2017-01-03 | 2012-05-31 | View | |
1217 | CVE-2008-1258 | Cross-site scripting (XSS) vulnerability in prim.htm on the D-Link DI-604 router allows remote attackers to inject arbitrary web script or HTML via the rf parameter. | 2 | 4.3 | Medium | 2017-01-03 | 2010-08-30 | View | |
1218 | CVE-2008-1259 | The Zyxel P-2602HW-D1A router with 3.40(AJZ.1) firmware maintains authentication state by IP address, which allows remote attackers to bypass authentication by establishing a session from a source IP address of a user who previously authenticated within the previous 5 minutes. | 2 | 9.3 | High | 2017-01-03 | 2008-09-05 | View | |
1219 | CVE-2008-1260 | Multiple cross-site request forgery (CSRF) vulnerabilities on the Zyxel P-2602HW-D1A router with 3.40(AJZ.1) firmware allow remote attackers to (1) make the admin web server available on the Internet (WAN) interface via the WWWAccessInterface parameter to Forms/RemMagWWW_1 or (2) change the IP whitelisting timeout via the StdioTimout parameter to Forms/rpSysAdmin_1. | 2 | 4.3 | Medium | 2017-01-03 | 2010-07-16 | View | |
1220 | CVE-2008-1261 | The Zyxel P-2602HW-D1A router with 3.40(AJZ.1) firmware provides different responses to admin page requests depending on whether a user is logged in, which allows remote attackers to obtain current login status by requesting an arbitrary admin URI. | 2 | 5 | Medium | 2017-01-03 | 2008-09-05 | View |
Page 244 of 17672, showing 5 records out of 88360 total, starting on record 1216, ending on 1220