Files
CVEs-PoC/2020/CVE-2020-16210.md
T
2024-05-25 21:48:12 +02:00

20 lines
1011 B
Markdown

### [CVE-2020-16210](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-16210)
![](https://img.shields.io/static/v1?label=Product&message=N-Tron%20702-W%20%2F%20702M12-W&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Vulnerability&message=IMPROPER%20NEUTRALIZATION%20OF%20INPUT%20DURING%20WEB%20PAGE%20GENERATION%20(%E2%80%98CROSS-SITE%20SCRIPTING%E2%80%99)%20CWE-79&color=brighgreen)
### Description
The affected product is vulnerable to reflected cross-site scripting, which may allow an attacker to remotely execute arbitrary code and perform actions in the context of an attacked user on the N-Tron 702-W / 702M12-W (all versions).
### POC
#### Reference
- http://packetstormsecurity.com/files/159064/Red-Lion-N-Tron-702-W-702M12-W-2.0.26-XSS-CSRF-Shell.html
- http://seclists.org/fulldisclosure/2020/Sep/6
#### Github
- https://github.com/404notf0und/CVE-Flow
- https://github.com/Live-Hack-CVE/CVE-2020-16210