Exploits / Vulnerability Discovered : 2019-03-04 |
Type : webapps |
Platform : hardware
This exploit / vulnerability Fiberhome an550604f rp2669 persistent crosssite scripting is for educational purposes only and if it is used you will do on your own risk!
Stored XSS occurs when a web application gathers input from a user which might be malicious, and then stores that input in a data store for later use. The input that is stored is not correctly filtered. As a consequence, the malicious data will appear to be part of the web site and run within the user’s browser under the privileges of the web application.
===========================================================================
1. Login with credential 192.168.1.1
2. Go to Management
3. Open User Account
4. Add user
5. Inject the post parameter "account_user"
6. Encode Url <script>alert("XSS")</script>