CVE-2016-2279
MEDIUMRockwell Automation CompactLogix 1769-L* < 28.011 - Cross-Site Scripting
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2016-2279. PoCs published by t4rkd3vilz.
AI-analyzed exploit summary This exploit demonstrates a reflected XSS vulnerability in Rockwell Scada System by injecting a JavaScript alert into the 'name' parameter of the SysDataDetail endpoint. The PoC is a simple URL-based attack that triggers when a user visits the crafted link.
Description
Cross-site scripting (XSS) vulnerability in the web server in Rockwell Automation Allen-Bradley CompactLogix 1769-L* before 28.011+ allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Exploits (1)
This exploit demonstrates a reflected XSS vulnerability in Rockwell Scada System by injecting a JavaScript alert into the 'name' parameter of the SysDataDetail endpoint. The PoC is a simple URL-based attack that triggers when a user visits the crafted link.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N