CVE-2017-6443
MEDIUMEPSON TMNet WebConfig 1.00 - Cross-Site Scripting via W_AD1 Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-6443. PoCs published by Michael Benich.
AI-analyzed exploit summary This exploit demonstrates a persistent XSS vulnerability in EPSON TMNet WebConfig Ver. 1.00 by injecting arbitrary JavaScript via an unsanitized POST parameter. The payload remains persistent and executes when users visit the main page.
Description
Cross-site scripting (XSS) vulnerability in EPSON TMNet WebConfig 1.00 allows remote attackers to inject arbitrary web script or HTML via the W_AD1 parameter to Forms/oadmin_1.
Exploits (1)
This exploit demonstrates a persistent XSS vulnerability in EPSON TMNet WebConfig Ver. 1.00 by injecting arbitrary JavaScript via an unsanitized POST parameter. The payload remains persistent and executes when users visit the main page.
References (3)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N