vendor:
DSL-500B G2
by:
Mauricio Corrêa
8.8
CVSS
HIGH
Cross Site Scripting (XSS Injection)
79
CWE
Product Name: DSL-500B G2
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2015
Exploit for D-Link DSL-500B G2 Cross Site Scripting (XSS Injection) Stored in todmngr.tod URL Filter
This exploit disables some features of the modem, forcing the administrator of the device, accessing the page to reconfigure the modem again, occurring script execution in the browser of internal network users.
Mitigation:
Ensure that user input is properly sanitized and validated before being used in web applications.