Exploitation Summary
EIP tracks 1 public exploit for CVE-2014-9143. PoCs published by Crash.
AI-analyzed exploit summary The exploit demonstrates a command injection vulnerability (CVE-2014-9144) in the ping field of a Technicolor DT5130 Wireless N ADSL 2/2+ Modem Router (Firmware V2.05.C29GV). It also includes examples of unauthenticated XSS (CVE-2014-9142) and arbitrary URL redirect (CVE-2014-9143).
Description
Open redirect vulnerability in Technicolor Router TD5130 with firmware 2.05.C29GV allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the failrefer parameter.
Exploits (1)
The exploit demonstrates a command injection vulnerability (CVE-2014-9144) in the ping field of a Technicolor DT5130 Wireless N ADSL 2/2+ Modem Router (Firmware V2.05.C29GV). It also includes examples of unauthenticated XSS (CVE-2014-9142) and arbitrary URL redirect (CVE-2014-9143).