目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2020-35262 PoC — Digisol Systems DG-HR3400 跨站脚本漏洞

来源
关联漏洞
标题: Digisol Systems DG-HR3400 跨站脚本漏洞 (CVE-2020-35262)
Description:Digisol Systems DG-HR3400是印度Digisol Systems公司的一款无线路由器。 Digisol DG-HR3400 存在跨站脚本漏洞,该漏洞源于系统时间中的NTP服务器名和URL过滤器中的“关键字”。
Description
Cross Site Scripting (XSS) in Digisol DG-HR3400 Router
介绍
# CVE-2020-35262: Stored XSS in Digisol DG-HR3400 Router

## **[Vulnerability Description]()**

It has been identified that the vulnerable endpoint doesn't have server side input validation and lacks client side filtering for any malicious script injection. An attacker can use this vulnerability to inject malicious script in the endpoint and the script is activated every time a user opens the vulnerable endpoint. Attackers can perform malicious operations using this vulnerability to take over the device and finally, to take over the network.

**Researcher:** Sayli Ambure (https://twitter.com/sayli_ambure)  

**MITRE CVE link:** https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-35262

## **[Proof-of-Concept Exploit:]()**

### **[1. NTP configuration in Maintenance module]()**

**Parameter: Server**

### **[Proof of Concept Video:]()**

<a href="http://www.youtube.com/watch?feature=player_embedded&v=E5wEzf-gkOE
" target="_blank"><img src="http://img.youtube.com/vi/E5wEzf-gkOE/0.jpg" 
 width="500" height="300" border="10" /></a>
 
 ### **[2. URL Blocking configuration in Advanced module]()**
 
 **Parameter: Keyword**
 
 ### **[Proof of Concept video:]()**
 
<a href="http://www.youtube.com/watch?feature=player_embedded&v=VJVjuLYbgcQ
" target="_blank"><img src="http://img.youtube.com/vi/VJVjuLYbgcQ/0.jpg" 
 width="500" height="300" border="10" /></a>
文件快照

登录后查看神龙缓存的 POC 文件快照

登录查看
备注
    1. 建议优先通过来源进行访问。
    2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
    3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →