Bugtraq mailing list archives

RE: THOMSON Router XSS


From: Auffret Patrice <Patrice.Auffret () technicolor com>
Date: Fri, 15 Apr 2011 17:15:50 +0200

#####################################################################
# Vendor: THOMSON Router
# Product Name:       TG585 v7
# Software Release: 7.4.4.7
# Vulnerability type: XSS
# Risk rating: Medium
#####################################################################
# [Exploit]
# http://[ROUTER_IP]/cgi/b/ic/connect/?url=<script>alert(1)</script>
#####################################################################
# [Credits]
# Edgard Chammas [454447415244]
# edgard.chammas () balamand edu lb
#####################################################################


Dear Mr Chammas,

Thank you for porting this security issue to our attention. This 
vulnerability was already known to our service, and we have fixed it 
since 8.2.7.6 release.

For your information, Technicolor products security issues may be 
reported to the following address: security_at_technicolor.com. So for 
you future potential findings, do not hesitate to directly contact us.

Technicolor is making its best to avoid security issues in its 
products, but we never be 100% sure we missed no one.

Best regards, Technicolor Security Team.

-- 
Patrice Auffret | Security Assessment Coordinator
Security and Content Protection Labs | Office of the CTO
+33 (0)2 99 27 3246 | +33 (0)6 81 98 8007


Current thread: