what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

APC Switched Rack PDU Cross Site Scripting

APC Switched Rack PDU Cross Site Scripting
Posted Dec 15, 2009
Authored by Jamal Pecou

The APC Switched Rack PDU suffers from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | c74663b043ce34b6f04fd6951f69dcbf99633d632f0599e026cd1f0bc29a903c

APC Switched Rack PDU Cross Site Scripting

Change Mirror Download
###########################################

#APC Switched Rack PDU XSS Vulnerability#
#By Jamal Pecou #
#jpecou (at) gmail (dot) c0m. #

###############Product Info#################

#Product Info(Tested Versions)#
Model = AP7932
Harware Revision = B2

#Application Module#
Name = rpdu
Version = v3.3.3(Tested First)
Version = 3.7.0(Current)

#APC OS (AOS)
Name = aos
Version = v3.3.4

###############Vulnerability################

XSS Vulnerability:

The APC Switch RACK PDU web administration login page is prone to a cross-site scripting vulnerability because the application fails to sufficiently sanitize user-supplied input.

The script "login1" located in the Forms directory fails to properly sanitize user input data in the login_username field

####################PoC#####################

Proof-of-Concept

http://<PDU IP>/Forms/login1?login_username=<ScRiPt>alert('hello');</ScRiPt>


################Additional#################

Jun 17th 2009 - Vulnerability Discovered

Jun 18th 2009 - Contacted Vendor

Jun 21st 2009 - APC Creates a ticket and enters finding into bug tracking database.

Dec 14th 2009 - APC, no patches released.

###########################################
Login or Register to add favorites

File Archive:

May 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    May 1st
    44 Files
  • 2
    May 2nd
    5 Files
  • 3
    May 3rd
    11 Files
  • 4
    May 4th
    0 Files
  • 5
    May 5th
    0 Files
  • 6
    May 6th
    28 Files
  • 7
    May 7th
    0 Files
  • 8
    May 8th
    0 Files
  • 9
    May 9th
    0 Files
  • 10
    May 10th
    0 Files
  • 11
    May 11th
    0 Files
  • 12
    May 12th
    0 Files
  • 13
    May 13th
    0 Files
  • 14
    May 14th
    0 Files
  • 15
    May 15th
    0 Files
  • 16
    May 16th
    0 Files
  • 17
    May 17th
    0 Files
  • 18
    May 18th
    0 Files
  • 19
    May 19th
    0 Files
  • 20
    May 20th
    0 Files
  • 21
    May 21st
    0 Files
  • 22
    May 22nd
    0 Files
  • 23
    May 23rd
    0 Files
  • 24
    May 24th
    0 Files
  • 25
    May 25th
    0 Files
  • 26
    May 26th
    0 Files
  • 27
    May 27th
    0 Files
  • 28
    May 28th
    0 Files
  • 29
    May 29th
    0 Files
  • 30
    May 30th
    0 Files
  • 31
    May 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close