ID

VAR-E-201804-0244


CVE

cve_id:CVE-2018-10110

Trust: 1.5

sources: PACKETSTORM: 147184 // EXPLOIT-DB: 44473

EDB ID

44473


TITLE

D-Link DIR-615 Wireless Router - Persistent Cross Site Scripting - Hardware remote Exploit

Trust: 0.6

sources: EXPLOIT-DB: 44473

DESCRIPTION

D-Link DIR-615 Wireless Router - Persistent Cross Site Scripting. CVE-2018-10110 . remote exploit for Hardware platform

Trust: 0.6

sources: EXPLOIT-DB: 44473

AFFECTED PRODUCTS

vendor:d linkmodel:dir-615 wireless routerscope: - version: -

Trust: 1.6

vendor:d linkmodel:dir-615scope: - version: -

Trust: 0.5

sources: PACKETSTORM: 147184 // EXPLOIT-DB: 44473 // EDBNET: 97513

EXPLOIT

######################################################################################
# Exploit Title: D-Link DIR-615 Wireless Router - Persistent Cross Site Scripting (XSS)
# Date: 14.04.2018
# Exploit Author: Sayan Chatterjee
# Vendor Homepage: http://www.dlink.co.in
# Hardware Link: http://www.dlink.co.in/products/?pid=678
# Category: Hardware (Wi-fi Router)
# Hardware Version: T1
# Firmware Version: 20.07
# Tested on: Windows 10
# CVE: CVE-2018-10110
#######################################################################################

Reproduction Steps:
------------------------------
1. Go to your wi-fi router gateway [i.e: http://192.168.0.1]
2. Go to –> “Maintenance” –> “Admin”
3. Create a user with name alert_"HI"
4. Refresh the page and you will be having “HI” popup

#######################################################################################

Trust: 1.0

sources: EXPLOIT-DB: 44473

EXPLOIT LANGUAGE

txt

Trust: 0.6

sources: EXPLOIT-DB: 44473

PRICE

free

Trust: 0.6

sources: EXPLOIT-DB: 44473

TYPE

Persistent Cross Site Scripting

Trust: 1.6

sources: EXPLOIT-DB: 44473 // EDBNET: 97513

TAGS

tag:exploit

Trust: 0.5

tag:xss

Trust: 0.5

sources: PACKETSTORM: 147184

CREDITS

Sayan Chatterjee

Trust: 0.6

sources: EXPLOIT-DB: 44473

EXTERNAL IDS

db:EXPLOIT-DBid:44473

Trust: 1.6

db:NVDid:CVE-2018-10110

Trust: 1.5

db:EDBNETid:97513

Trust: 0.6

db:PACKETSTORMid:147184

Trust: 0.5

sources: PACKETSTORM: 147184 // EXPLOIT-DB: 44473 // EDBNET: 97513

REFERENCES

url:https://nvd.nist.gov/vuln/detail/cve-2018-10110

Trust: 1.5

url:https://www.exploit-db.com/exploits/44473/

Trust: 0.6

sources: PACKETSTORM: 147184 // EXPLOIT-DB: 44473 // EDBNET: 97513

SOURCES

db:PACKETSTORMid:147184
db:EXPLOIT-DBid:44473
db:EDBNETid:97513

LAST UPDATE DATE

2022-07-27T09:47:01.739000+00:00


SOURCES RELEASE DATE

db:PACKETSTORMid:147184date:2018-04-17T13:21:45
db:EXPLOIT-DBid:44473date:2018-04-17T00:00:00
db:EDBNETid:97513date:2018-04-17T00:00:00