Skip to content

Instantly share code, notes, and snippets.

@shiham101
Last active January 31, 2019 07:58
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save shiham101/d8f98d4ce302c12576f39af2ad2448ca to your computer and use it in GitHub Desktop.
Save shiham101/d8f98d4ce302c12576f39af2ad2448ca to your computer and use it in GitHub Desktop.
CVE-2017-16765
> XSS exists on D-Link DWR-933 1.00(WW)B17 devices via cgi-bin/gui.cgi.
>
> ------------------------------------------
>
> [Additional Information]
> url:cgi-bin/gui.cgi
> payload :<img src=x onerror=alert(1)>
>
> ------------------------------------------
>
> [Vulnerability Type]
> Cross Site Scripting (XSS)
>
> ------------------------------------------
>
> [Vendor of Product]
> Dlink
>
> ------------------------------------------
>
> [Affected Product Code Base]
> DWR-933 - 1.00(WW)B17
>
> ------------------------------------------
>
> [Affected Component]
> gui.cgi
>
> ------------------------------------------
>
> [Attack Type]
> Remote
>
> ------------------------------------------
>
> [Impact Code execution]
> true
>
> ------------------------------------------
>
> [Attack Vectors]
> action parameter in http post
>
> ------------------------------------------
>
> [Discoverer]
> CHT Security-hans
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment