CVE Database
/

CVE-2013-5223

Back to search

CVE-2013-5223

Published: Nov 15, 2013

Modified: Oct 22, 2025

PUBLISHED

Description

Multiple cross-site scripting (XSS) vulnerabilities in D-Link DSL-2760U Gateway (Rev. E1) allow remote authenticated users to inject arbitrary web script or HTML via the (1) ntpServer1 parameter to sntpcfg.cgi, username parameter to (2) ddnsmngr.cmd or (3) todmngr.tod, (4) TodUrlAdd parameter to urlfilter.cmd, (5) appName parameter to scprttrg.cmd, (6) fltName in an add action or (7) rmLst parameter in a remove action to scoutflt.cmd, (8) groupName parameter to portmapcfg.cmd, (9) snmpRoCommunity parameter to snmpconfig.cgi, (10) fltName parameter to scinflt.cmd, (11) PolicyName in an add action or (12) rmLst parameter in a remove action to prmngr.cmd, (13) ippName parameter to ippcfg.cmd, (14) smbNetBiosName or (15) smbDirName parameter to samba.cgi, or (16) wlSsid parameter to wlcfg.wl.

VendorProductVersions

n/a

n/a

affected
n/a

References

99611
vdb-entry
x_refsource_OSVDB
99609
vdb-entry
x_refsource_OSVDB
dlink-cve20135223-xss(88723)
vdb-entry
x_refsource_XF
99605
vdb-entry
x_refsource_OSVDB
99607
vdb-entry
x_refsource_OSVDB
99608
vdb-entry
x_refsource_OSVDB
99606
vdb-entry
x_refsource_OSVDB
99610
vdb-entry
x_refsource_OSVDB
99604
vdb-entry
x_refsource_OSVDB
99615
vdb-entry
x_refsource_OSVDB
99603
vdb-entry
x_refsource_OSVDB
99612
vdb-entry
x_refsource_OSVDB
99616
vdb-entry
x_refsource_OSVDB
99613
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now