<!-" sequence in an HTTP GET request in the logon, possibly due to a cross-site s...">
CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
NONE
AV:N/AC:M/Au:N/C:N/I:P/A:N
AI Score
Confidence
High
EPSS
Percentile
58.5%
The web server control panel in 602LAN SUITE 2004 allows remote attackers to make it more difficult for the administrator to read portions of log files via a “</pre><!-” sequence in an HTTP GET request in the logon, possibly due to a cross-site scripting (XSS) vulnerability.
Vendor | Product | Version | CPE |
---|---|---|---|
software602 | 602lan_suite | 2004 | cpe:2.3:a:software602:602lan_suite:2004:*:*:*:*:*:*:* |