CVE-2007-4488

N/A Unknown
Published: August 22, 2007 Modified: April 23, 2026
View on NVD

Description

Multiple cross-site scripting (XSS) vulnerabilities in the Siemens Gigaset SE361 WLAN router with firmware 1.00.0 allow remote attackers to inject arbitrary web script or HTML via the portion of the URI immediately following the filename for (1) a GIF filename, which triggers display of the GIF file in text format and an unspecified denial of service (crash); or (2) the login.tri filename, which triggers a continuous loop of the browser attempting to visit the login page.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://osvdb.org/45841
Source: cve@mitre.org
http://osvdb.org/45842
Source: cve@mitre.org
http://osvdb.org/45841
Source: af854a3a-2127-422b-91ae-364da2661108
http://osvdb.org/45842
Source: af854a3a-2127-422b-91ae-364da2661108
http://securityreason.com/securityalert/3050
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/archive/1/477220/100/0/threaded
Source: af854a3a-2127-422b-91ae-364da2661108

8 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
0.3%
56th percentile
Exploitation Status
Not in CISA KEV

Affected Vendors

siemens