CVE-2011-5283
Smoothwall Express 3.1 and 3.0 SP3 - Cross-Site Scripting via IP Parameter in ipinfo.cgi
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2011-5283. PoCs published by dave b.
AI-analyzed exploit summary The exploit demonstrates XSS and CSRF vulnerabilities in SmoothWall Express 3.0's web management interface. The XSS payload injects a script via the 'IP' parameter, while the CSRF example forces a reboot action without user interaction.
Description
Cross-site scripting (XSS) vulnerability in the web management interface in httpd/cgi-bin/ipinfo.cgi in Smoothwall Express 3.1 and 3.0 SP3 and earlier allows remote attackers to inject arbitrary web script or HTML via the IP parameter in a Run action.
Exploits (1)
The exploit demonstrates XSS and CSRF vulnerabilities in SmoothWall Express 3.0's web management interface. The XSS payload injects a script via the 'IP' parameter, while the CSRF example forces a reboot action without user interaction.