CVE-2014-1407
10.01.2014, 16:47
Multiple cross-site scripting (XSS) vulnerabilities on the Conceptronic C54APM access point with runtime code 1.26 allow remote attackers to inject arbitrary web script or HTML via (1) the submit-url parameter in a Refresh action to goform/formWlSiteSurvey or (2) the wlan-url parameter to goform/formWlanSetup.
Vendor | Product | Version |
---|---|---|
conceptronic | c54apm_firmware | 1.26 |
𝑥
= Vulnerable software versions