ID

VAR-E-201403-0281


TITLE

Ubee EVW3200 Cross Site Scripting

Trust: 0.5

sources: PACKETSTORM: 125703

DESCRIPTION

Ubee EVW3200 suffers from multiple persistent cross site scripting vulnerabilities.

Trust: 0.5

sources: PACKETSTORM: 125703

AFFECTED PRODUCTS

vendor:ubeemodel:evw3200scope: - version: -

Trust: 0.5

sources: PACKETSTORM: 125703

EXPLOIT

# Exploit Title: Ubee EVW3200 - Multiple Persistent Cross Site Scripting

# Google Dork: N/A

# Date: 02-03-2014

# Exploit Author: Jeroen - IT Nerdbox

# Vendor Homepage: http://www.ubeeinteractive.com/

# Software Link:
http://www.ubeeinteractive.com/products/cable?field_product_catetory_tid=20

# Version: All

# Tested on: N/A

# CVE : N/A

#

## Description:

#

# The SSID and Device name settings in the wireless configuration do not
sanitize their input.

#

# The VPN Tunnel name is also vulnerable for persistent XSS

#

## PoC:

#

# Entering the following payload in one of these fields will execute
javascript:

#

# "><input onmouseover=prompt(1)> or "><button
onclick=prompt(1)>XSS</button>

#

#

# More information can be found at:
http://www.nerdbox.it/ubee-evw3200-multiple-vulnerabilities/

Trust: 0.5

sources: PACKETSTORM: 125703

EXPLOIT HASH

LOCAL

SOURCE

md5: 5206f6bd3915fc2f9a4a1ec5854b4839
sha-1: f957633e3408cfad3d972254617c2da36bb2f62a
sha-256: 9cd81f9687fbcf20d9e66b8a26971e454bf020fbfa8a43c4dc7eb473cd8e9b57
md5: 5206f6bd3915fc2f9a4a1ec5854b4839

Trust: 0.5

sources: PACKETSTORM: 125703

PRICE

free

Trust: 0.5

sources: PACKETSTORM: 125703

TYPE

xss

Trust: 0.5

sources: PACKETSTORM: 125703

TAGS

tag:exploit

Trust: 0.5

tag:vulnerability

Trust: 0.5

tag:xss

Trust: 0.5

sources: PACKETSTORM: 125703

CREDITS

Jeroen

Trust: 0.5

sources: PACKETSTORM: 125703

EXTERNAL IDS

db:PACKETSTORMid:125703

Trust: 0.5

sources: PACKETSTORM: 125703

SOURCES

db:PACKETSTORMid:125703

LAST UPDATE DATE

2022-07-27T09:58:47.410000+00:00


SOURCES RELEASE DATE

db:PACKETSTORMid:125703date:2014-03-13T14:55:55