Home[1] Files[2] News[3] &[SERVICES_TAB] Contact[4] Add New[5]
- Dinstar FXO Analog VoIP Gateway DAG2000-16O Cross Site Scripting[6]
- Authored by Yehia Elghaly[7]
-
Dinstar FXO Analog VoIP Gateway version DAG2000-16O suffers from a persistent cross site scripting vulnerability.
- SHA-256 |
97eaa1028dd6a201c66d40bfa6162f161c2586c5696100d18bc50025c51b3882
- Download[8] | Favorite[9] | View[10]
Change Mirror[11] Download[12]
# Exploit Title: Dinstar FXO Analog VoIP Gateway DAG2000-16O Stored Cross Site Scripting
# Google Dork: NA
# Date: 25/10/2022
# Exploit Author: Yehia Elghaly
# Vendor Homepage: https://www.dinstar.com/
# Software Link: https://www.dinstar.com/analog-voip-gateway/16-fxo/
# Version: DAG2000-16O
# CVE: N/A
Summary: DAG1000-16O FXO analog gateway is a type of access gateway offering seamless connectivity between IP-based telephony networks and legacy telephones (POTS) and PBX systems. The analog gateway has 16 FXO ports and is used to connect to analog PBX or the PSTN lines of telecom carriers. With the standard SIP protocol, it's compatible with leading IMS/NGN platforms and SIP-based IP Phone systems. It provides low-cost and easy-to-use VoIP solutions for small and medium businesses, call centers, SOHO, remote offices as well as enterprises with multiple branches.
Description: The attacker can able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.: Stored XSS found on when (Add new Port) affected field is (Primary Authenticate ID)
Payload: <script>alert(44)</script>
[Affected Component]
(Add new Port)--> (Primary Authenticate ID)
File Tags
- ActiveX[17] (932)
- Advisory[18] (79,155)
- Arbitrary[19] (15,580)
- BBS[20] (2,859)
- Bypass[21] (1,608)
- CGI[22] (1,014)
- Code Execution[23] (6,820)
- Conference[24] (672)
- Cracker[25] (840)
- CSRF[26] (3,282)
- DoS[27] (22,411)
- Encryption[28] (2,346)
- Exploit[29] (50,224)
- File Inclusion[30] (4,161)
- File Upload[31] (945)
- Firewall[32] (821)
- Info Disclosure[33] (2,647)
- Intrusion Detection[34] (863)
- Java[35] (2,881)
- JavaScript[36] (814)
- Kernel[37] (6,220)
- Local[38] (14,146)
- Magazine[39] (586)
- Overflow[40] (12,318)
- Perl[41] (1,417)
- PHP[42] (5,076)
- Proof of Concept[43] (2,286)
- Protocol[44] (3,406)
- Python[45] (1,436)
- Remote[46] (29,953)
- Root[47] (3,488)
- Ruby[48] (593)
- Scanner[49] (1,631)
- Security Tool[50] (7,753)
- Shell[51] (3,094)
- Shellcode[52] (1,204)
- Sniffer[53] (884)
- Spoof[54] (2,145)
- SQL Injection[55] (16,078)
- TCP[56] (2,373)
- Trojan[57] (682)
- UDP[58] (873)
- Virus[59] (660)
- Vulnerability[60] (30,958)
- Web[61] (9,283)
- Whitepaper[62] (3,724)
- x86[63] (944)
- XSS[64] (17,460)
- Other[65]
File Archives
- October 2022[66]
- September 2022[67]
- August 2022[68]
- July 2022[69]
- June 2022[70]
- May 2022[71]
- April 2022[72]
- March 2022[73]
- February 2022[74]
- January 2022[75]
- December 2021[76]
- November 2021[77]
- Older[78]
Systems
- AIX[79] (426)
- Apple[80] (1,901)
- BSD[81] (369)
- CentOS[82] (55)
- Cisco[83] (1,916)
- Debian[84] (6,592)
- Fedora[85] (1,690)
- FreeBSD[86] (1,242)
- Gentoo[87] (4,228)
- HPUX[88] (878)
- iOS[89] (324)
- iPhone[90] (108)
- IRIX[91] (220)
- Juniper[92] (67)
- Linux[93] (43,800)
- Mac OS X[94] (684)
- Mandriva[95] (3,105)
- NetBSD[96] (255)
- OpenBSD[97] (479)
- RedHat[98] (12,151)
- Slackware[99] (941)
- Solaris[100] (1,607)
- SUSE[101] (1,444)
- Ubuntu[102] (8,090)
- UNIX[103] (9,134)
- UnixWare[104] (185)
- Windows[105] (6,489)
- Other[106]