Podatność typu stored XSS w endpoint'cie PwdGrp.cgi urządzenia AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 umożliwia atakującym wykonanie dowolnych skryptów web lub HTML poprzez wstrzyknięcie spreparowanego payload'u w pole username.
▸ Pokaż oryginał (EN)
A stored cross-site scripting (XSS) vulnerability in the PwdGrp.cgi endpoint of AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the username field.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NAvtech Dgm1104
HWAvtechwszystkie wersjeAvtech Dgm1104 Firmware
OSAvtechwszystkie wersje
Powiązane podatności
AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated com...
AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated com...
AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated com...
AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 zawiera podatność command injection w funkcji ...
AVTECH EagleEyes — pominięcie weryfikacji domeny TLS (ALLOW_ALL_HOSTNAME_VERIFIER)