ID

VAR-E-201011-0642


EDB ID

35012


TITLE

ZYXEL P-660R-T1 V2 - 'HomeCurrent_Date' Cross-Site Scripting - Multiple webapps Exploit

Trust: 0.6

sources: EXPLOIT-DB: 35012

DESCRIPTION

ZYXEL P-660R-T1 V2 - 'HomeCurrent_Date' Cross-Site Scripting.. webapps exploit for Multiple platform

Trust: 0.6

sources: EXPLOIT-DB: 35012

AFFECTED PRODUCTS

vendor:zyxelmodel:p-660r-t1scope:eqversion:v2

Trust: 1.6

vendor:zyxelmodel:p-660r-t1scope:eqversion:v20

Trust: 0.3

sources: BID: 45027 // EXPLOIT-DB: 35012 // EDBNET: 56262

EXPLOIT

source: https://www.securityfocus.com/bid/45027/info

ZyXEL P-660R-T1 V2 is prone to a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied data.

An attacker may leverage this issue to execute arbitrary HTML and script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.

http://www.example.com/Forms/home_1?&HomeCurrent_Date=&#039;<sCript>alert(1);</ScRiPt>&#039;01%2F01%2F2000

Trust: 1.0

sources: EXPLOIT-DB: 35012

EXPLOIT LANGUAGE

txt

Trust: 0.6

sources: EXPLOIT-DB: 35012

PRICE

free

Trust: 0.6

sources: EXPLOIT-DB: 35012

TYPE

'HomeCurrent_Date' Cross-Site Scripting

Trust: 1.0

sources: EXPLOIT-DB: 35012

CREDITS

Usman Saeed

Trust: 0.6

sources: EXPLOIT-DB: 35012

EXTERNAL IDS

db:EXPLOIT-DBid:35012

Trust: 1.9

db:BIDid:45027

Trust: 1.9

db:EDBNETid:56262

Trust: 0.6

sources: BID: 45027 // EXPLOIT-DB: 35012 // EDBNET: 56262

REFERENCES

url:https://www.securityfocus.com/bid/45027/info

Trust: 1.0

url:https://www.exploit-db.com/exploits/35012/

Trust: 0.6

url:https://www.exploit-db.com/exploits/35012

Trust: 0.3

url:http://www.zyxel.com/web/product_category.php?pc1indexflag=20040812093058

Trust: 0.3

sources: BID: 45027 // EXPLOIT-DB: 35012 // EDBNET: 56262

SOURCES

db:BIDid:45027
db:EXPLOIT-DBid:35012
db:EDBNETid:56262

LAST UPDATE DATE

2022-07-27T09:38:23.960000+00:00


SOURCES UPDATE DATE

db:BIDid:45027date:2010-11-23T00:00:00

SOURCES RELEASE DATE

db:BIDid:45027date:2010-11-23T00:00:00
db:EXPLOIT-DBid:35012date:2010-11-23T00:00:00
db:EDBNETid:56262date:2010-11-23T00:00:00