RULE(RULE ID:324233)

Rule General Information
Release Date: 2020-01-20
Rule Name: Multiple ADSL Routers Directory Traversal Vulnerability (CVE-2015-7252)
Severity:
CVE ID:
Rule Protection Details
Description: Cross-site scripting (XSS) vulnerability in cgi-bin/webproc on ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE allows remote attackers to inject arbitrary web script or HTML via the errorpage parameter.
Impact: An attacker can abtain sensitive information of the target victim, and do malicious actions to gain profits using the information.
Affected OS: Network Device
Reference: SecurityFocusBID:77421
ExploitDB:38773
https://www.kb.cert.org/vuls/id/391604
https://www.kb.cert.org/vuls/id/BLUU-9ZDJWA
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
http://www.zte.com.cn/