drive.google.com
https://drive.google.com/open?id=1WkmtsCVNCtxwWH2fe9DtHow_Nedp1a7j CVE-2019-11370
MEDIUMNuclei
carel pcoweb_card_firmware Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Record summary
CVE-2019-11370 has a selected CVSS score of 5.4 (medium); EIP currently links 1 catalogued exploit and 1 Nuclei template.
Description
Stored XSS was discovered in Carel pCOWeb prior to B1.2.4, as demonstrated by the config/pw_snmp.html "System contact" field.
Description source: CVE List
Exploitation context
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
pcoweb_card_firmwareBrowse carel / pcoweb_card_firmware | VulnCheck | Version data not supplied | |
Proofs of concept
1Catalogued exploits
ExploitDBCarel pCOWeb < B1.2.1 - Cross-Site ScriptingExploitDB exploitby Luca.ChiouNot analyzed1 file
Nuclei templates
1ProjectDiscoveryMEDIUMCarel pCOWeb <B1.2.4 - Cross-Site ScriptingCVSS 5.4
Carel pCOWeb prior to B1.2.4 is vulnerable to stored cross-site scripting, as demonstrated by the config/pw_snmp.html "System contact" field.
Impact
Allows attackers to inject malicious scripts into web pages viewed by users, leading to potential data theft or unauthorized actions.
Remediation
Apply the latest patch or upgrade to a version that addresses the vulnerability.
WeaknessesCWE-79
Authorsarafatansari
Template tagscvecve2019pcowebxsscareledbvkevvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:o:carel:pcoweb_card_firmware:*:*:*:*:*:*:*:*
Shodan: http.html:"pCOWeb"
Shodan: http.html:"pcoweb"
FOFA: body="pcoweb"
https://www.exploit-db.com/exploits/46897 https://github.com/nepenthe0320/cve_poc/blob/master/CVE-2019-11370 https://nvd.nist.gov/vuln/detail/CVE-2019-11370 https://github.com/ARPSyndicate/kenzer-templates
Source: ProjectDiscovery
References
3github.com
https://github.com/nepenthe0320/cve_poc/blob/master/CVE-2019-11370 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-11370