Exploitation Summary
EIP tracks 1 public exploit for CVE-2014-9142. PoCs published by Crash.
AI-analyzed exploit summary The exploit demonstrates a command injection vulnerability (CVE-2014-9144) in the ping field of a Technicolor DT5130 Wireless N ADSL 2/2+ Modem Router (Firmware V2.05.C29GV). It also includes examples of unauthenticated XSS (CVE-2014-9142) and arbitrary URL redirect (CVE-2014-9143).
Description
Cross-site scripting (XSS) vulnerability in Technicolor Router TD5130 with firmware 2.05.C29GV allows remote attackers to inject arbitrary web script or HTML via the failrefer parameter.
Exploits (1)
The exploit demonstrates a command injection vulnerability (CVE-2014-9144) in the ping field of a Technicolor DT5130 Wireless N ADSL 2/2+ Modem Router (Firmware V2.05.C29GV). It also includes examples of unauthenticated XSS (CVE-2014-9142) and arbitrary URL redirect (CVE-2014-9143).