CVE-2019-11017
MEDIUMD-Link DI-524 2.06RU - Stored and Reflected Cross-Site Scripting via Web Configuration
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2019-11017. PoCs published by Semen Alexandrovich Lyhin.
AI-analyzed exploit summary This is a writeup describing multiple stored and reflected XSS vulnerabilities in D-Link DI-524 routers. It provides details on how to exploit these vulnerabilities, including example payloads and affected pages.
Description
On D-Link DI-524 V2.06RU devices, multiple Stored and Reflected XSS vulnerabilities were found in the Web Configuration: /spap.htm, /smap.htm, and /cgi-bin/smap, as demonstrated by the cgi-bin/smap RC parameter.
Exploits (1)
This is a writeup describing multiple stored and reflected XSS vulnerabilities in D-Link DI-524 routers. It provides details on how to exploit these vulnerabilities, including example payloads and affected pages.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N