ID

VAR-E-201405-0431


TITLE

Netgear DGN2200 Cross Site Scripting

Trust: 0.5

sources: PACKETSTORM: 126435

DESCRIPTION

Netgear DGN2200 suffers from a stored cross site scripting vulnerability.

Trust: 0.5

sources: PACKETSTORM: 126435

AFFECTED PRODUCTS

vendor:netgearmodel:dgn2200scope: - version: -

Trust: 0.5

sources: PACKETSTORM: 126435

EXPLOIT

# Exploit Title: Stored XSS Vulnerability in NETGEAR DGN2200 Web interface

# Date 30/04/2014

# Exploit author: Dolev Farhi @f1nhack

# Vendor homepage: http://netgear.com

# Affected Firmware version: 1.0.0.29_1.7.29_HotS

# Affected Hardware: NETGEAR DGN2200 Wireless ADSL Router




Summary
=======
NETGEAR DGN2200 ADSL router web interface suffers from persistent XSS vulnerability in the QoS(Quality of Service) Administration page under 'Expert Mode'.



Vulnerability Description
=========================
Persistent Cross Site Scripting



Steps to reproduce / PoC:
=========================
1. Login to the router web interface

2. Enter expert mode

3. navigate to QoS page

4. Add QoS Rule, or Edit an existing one.

5. in "QoS Policy for: " Enter the following: <script>alert("XSS")</script> and click apply.

6. go to another page and navigate back into QoS - the XSS error pops up.
- PoC Video: https://www.youtube.com/watch?v=xxjluF2RR70

Trust: 0.5

sources: PACKETSTORM: 126435

EXPLOIT HASH

LOCAL

SOURCE

md5: f514161b2d632bd919c1ca412b293831
sha-1: 2b1c5a68d9a52524215a9d3637dfc1eda3582846
sha-256: 222353a40c7c7515f7b22a5270e65688a7bc1b700e4f72fa8883849562b8f361
md5: f514161b2d632bd919c1ca412b293831

Trust: 0.5

sources: PACKETSTORM: 126435

PRICE

free

Trust: 0.5

sources: PACKETSTORM: 126435

TYPE

xss

Trust: 0.5

sources: PACKETSTORM: 126435

TAGS

tag:exploit

Trust: 0.5

tag:xss

Trust: 0.5

sources: PACKETSTORM: 126435

CREDITS

Dolev Farhi

Trust: 0.5

sources: PACKETSTORM: 126435

EXTERNAL IDS

db:PACKETSTORMid:126435

Trust: 0.5

sources: PACKETSTORM: 126435

SOURCES

db:PACKETSTORMid:126435

LAST UPDATE DATE

2022-07-27T09:30:06.311000+00:00


SOURCES RELEASE DATE

db:PACKETSTORMid:126435date:2014-05-02T06:28:50