Exploit/Advisories no image

Published on August 11th, 2022 📆 | 8198 Views ⚑

0

Intelbras ATA 200 Cross Site Scripting – Torchsec


iSpeech

# Exploit Title: Intelbras ATA 200 Authenticated Stored XSS
# Date: 17/01/2022
# Exploit Author: Leonardo Goncalves
# Vendor Homepage: https://www.intelbras.com/pt-br/adaptador-ip-para-telefones-analogicos-ata-200
# Version: Firmware 74.19.10.21

1) Log in the equipment via your web browser
2) Go to Management > Syslog
3) In the "Field Server Address" inject the payload "-prompt("XSS")-"
4) Click Save
5) Exploit





Source link

Tagged with:



Comments are closed.