Lucene search

K
zdiRicky "HeadlessZeke" Lawshae of HP DVLabsZDI-14-371
HistoryNov 03, 2014 - 12:00 a.m.

(0Day) Denon AVR-3313CI 'Friendlyname' Persistent Cross-Site Scripting Vulnerability

2014-11-0300:00:00
Ricky "HeadlessZeke" Lawshae of HP DVLabs
www.zerodayinitiative.com
13

0.007 Low

EPSS

Percentile

80.5%

This vulnerability allows remote attackers to insert persistent JavaScript on vulnerable installations of the Denon AVR-3313CI audio/video receiver’s web portal. Authentication is not required to persist the attack. However, user interaction is required to exploit this vulnerability in that the target must visit a malicious page. The specific flaw exists within parameters used by s_network.asp which does not properly sanitize user-supplied data. Some parameter values are used on multiple pages and the injected JavaScript will therefore run when any user views any of those pages, including the portal’s landing page.

0.007 Low

EPSS

Percentile

80.5%

Related for ZDI-14-371