vendor:
DSL-2730B
by:
Mauricio Correa
7.5
CVSS
HIGH
Cross Site Scripting (XSS Injection)
79
CWE
Product Name: DSL-2730B
Affected Version From: GE 1.01
Affected Version To: GE 1.01
Patch Exists: NO
Related CWE: N/A
CPE: dlink:dsl-2730b:c1
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 8 and Linux
2015
D-Link DSL-2730B Modem dnsProxy.cmd Exploit XSS Injection Stored
This exploit enables some features of the modem, forcing the administrator of the device, accessing the page to reconfigure the modem again, occurring script execution in the browser of internal network users.
Mitigation:
Ensure that user input is properly sanitized and validated before being used in the application.