Allied Telesis 8100L / 8 dispositivi consentono XSS tramite il parametro edit-ipv4_interface.php vlanid o subnet_mask. |
http://packetstormsecurity.com/files/151327/SirsiDynix-e-Library-3.5.x-Cross-Site-Scripting.html https://pentest.com.tr/exploits/Allied-Telesis-8100L-8-Cross-Site-Scripting.html https://www.exploit-db.com/exploits/46237/ https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-20503 |
Vulnerabilità: CVE-2018-20503
