Unrated severityNVD Advisory· Published May 13, 2008· Updated Apr 23, 2026
CVE-2008-2167
CVE-2008-2167
Description
Cross-site scripting (XSS) vulnerability in ZyXEL ZyWALL 100 allows remote attackers to inject arbitrary web script or HTML via the Referer header, which is not properly handled in a 404 Error page.
Affected products
1- cpe:2.3:h:zyxel:zywall_100:*:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- lists.grok.org.uk/pipermail/full-disclosure/2008-May/062152.htmlnvdExploit
- www.securityfocus.com/bid/29110nvdExploit
- secunia.com/advisories/30142nvdVendor Advisory
- securityreason.com/securityalert/3869nvd
- www.securityfocus.com/archive/1/491818/100/0/threadednvd
- www.securitytracker.com/idnvd
- www.vupen.com/english/advisories/2008/1501/referencesnvd
- exchange.xforce.ibmcloud.com/vulnerabilities/42282nvd
News mentions
0No linked articles in our index yet.