D-Link DAP-2253 Router Cross Site Scripting and Cross Site Request Forgery Vulnerabilities

D-Link DAP-2253 router is prone to a cross-site scripting vulnerability and a cross-site request-forgery vulnerability.

An attacker may exploit these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, steal cookie-based authentication credentials, perform unauthorized actions, and disclose or modify sensitive information. Other attacks may also be possible.

D-Link DAP-2253 running firmware 1.26rc55 and prior are vulnerable.


Privacy Statement
Copyright 2010, SecurityFocus