XSS exists on D-Link DWR-933 1.00(WW)B17 devices via cgi-bin/gui.cgi.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://gist.github.com/shiham101/d8f98d4ce302c12576f39af2ad2448ca | issue tracking exploit third party advisory |