VDB
CVE-2014-2045
CVE-2014-2045
PUBLISHED
CVSS 6.099999904632568 MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in the old and new interfaces in Viprinet Multichannel VPN Router 300 allow remote attackers to inject arbitrary web script or HTML via the username when (1) logging in or (2) creating an account in the old interface, (3) username when creating an account in the new interface, (4) hostname in the old interface, (5) inspect parameter in the config module, (6) commands parameter in the atcommands tool, or (7) host parameter in the ping tool.
EPSS 3.97% · 88.6th percentile
Risk Scores
CVSS 3.0
6.099999904632568
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS Score
3.97%
88.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| viprinet | multichannel_vpn_router_300_firmware | 2013080900, 2013070830 |
| n/a | n/a | n/a |
Exploit Intelligence
- 20160203 Security Advisories (circl)
- 20160203 Security Advisories (circl)
- http://packetstormsecurity.com/files/135613/Viprinet-Multichannel-VPN-Router-300-Cross-Site-Scripting.html (vulncheck-nvd)
- https://www.portcullis-security.com/security-research-and-downloads/security-advisories/cve-2014-2045/ (vulncheck-nvd)
- 39407 (cve.org)
- Viprinet Multichannel VPN Router 300 - Persistent Cross-Site Scripting (0day-today)
- Viprinet Multichannel VPN Router 300 - Persistent Cross-Site Scripting (0day-today)
Timeline
- Feb 3, 2016 CVE Published
- Feb 3, 2016 PoC Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Sep 3, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 8, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 16, 2023 EPSS Score
References
- http://packetstormsecurity.com/files/135613/Viprinet-Multichannel-VPN-Router-300-Cross-Site-Scripting.html url
- 20160203 Security Advisories mailing-list
- https://www.portcullis-security.com/security-research-and-downloads/security-advisories/cve-2014-2045/ url
- 39407 exploit
- 20160203 Security Advisories mailing-list
- https://nvd.nist.gov/vuln/detail/CVE-2014-2045 advisory
- https://www.exploit-db.com/exploits/39407 url
- https://www.portcullis-security.com/security-research-and-downloads/security-advisories/cve-2014-2045 url