Re: [FD] Reflected Cross-Site Scripting within the ASUS RT-AC68U Managing Web Interface

2014-04-06 Thread Palula Brasil
"fun; i keep waiting for these vulns to get old, but it's just still funny, every time!" And seems to me that not all XSS vulnerabilities are being dealt with in an extensive manner. So, albeit dealing with this specific vulnerability in 5 days, looks like ASUS is dealing with XSS vulnerabilities

Re: [FD] Reflected Cross-Site Scripting within the ASUS RT-AC68U Managing Web Interface

2014-04-06 Thread coderman
On Fri, Apr 4, 2014 at 11:08 AM, Palula Brasil wrote: >... > Reflected Cross-Site Scripting within the ASUS RT-AC68U Managing Web > Interface > ... > * Impact: This vulnerability allows for performing attacks against third party > users of the ASUS RT-AC68U web management platform, by

[FD] Reflected Cross-Site Scripting within the ASUS RT-AC68U Managing Web Interface

2014-04-04 Thread Palula Brasil
=[Alligator Security Team - Security Advisory] Reflected Cross-Site Scripting within the ASUS RT-AC68U Managing Web Interface Author: Joaquim Brasil de Oliveira < palulabrasil () gmail com > < twitter.com/palulabr > =