what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

ZO Tech Multiple Print Server Cross Site Scripting

ZO Tech Multiple Print Server Cross Site Scripting
Posted Apr 4, 2011
Authored by b0telh0 | Site gotgeek.com.br

ZO Tech Multiple Print Servers suffer from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | 5b76398f48aeff7943f4af61b9f875a7a6058d249a9099a8ecd83c597a68bb53

ZO Tech Multiple Print Server Cross Site Scripting

Change Mirror Download
GotGeek Labs
http://www.gotgeek.com.br/

ZO Tech Multiple Print Servers Cross-site Scripting Vulnerability



[+] Description

(1) PA101 Fast Parallel Port Print Server
(2) PU201 Fast USB Print Server
(3) PA301 Parallel Port Print Server
(4) PS531 USB & Parallel Print Server



[+] Information

Title: ZO Tech Multiple Print Servers Cross-site Scripting Vulnerability
Shodan Dork: ZOT-PS-30/8.3.0016 -WWW-Authenticate
ZOT-PS-47/9.8.0016 -WWW-Authenticate
ZOT-PS-34/8.3.0019 -WWW-Authenticate
ZOT-PS-39/6.3.0007 -WWW-Authenticate
Advisory: gg-009-2011
Date: 03-15-2011
Last update: 03-26-2011
Link: http://www.gotgeek.com.br/pocs/gg-009-2011.txt



[+] Vulnerabilities

Stored Cross-site Scripting:
Web interface from PA101, PU201, PA301 and PS531 Print Servers are affected by stored
cross-site scripting vulnerability because it fails to properly sanitize
user-supplied input at "NDSContext" field in "NetWare NDS Settings" area.
An attacker may leverage this issue to execute arbitrary script code
in the browser of an unsuspecting user in the context of the affected site.

After injecting the XSS code, you need to access Netware status page.


Affected Versions:

ZO Tech PA101 Fast Parallel Port Print Server
Firmware: 8.03.30F 0016 (ZOT-PS-30/8.3.0016)
8.03.30F 0014 (ZOT-PS-30/8.3.0014)
8.03.30F 0011 (ZOT-PS-30/8.3.0011)
8.03.30F 0009 (ZOT-PS-30/8.3.0009)
8.03.30F 0008 (ZOT-PS-30/8.3.0008)
8.03.30F 0007 (ZOT-PS-30/8.3.0007)

ZO Tech PU201 Fast USB Print Server
Firmware: 9.08.47F 0016 (ZOT-PS-47/9.8.0016)
9.08.47F 0015 (ZOT-PS-47/9.8.0015)
6.03.35F 0008 (ZOT-PS-35/6.3.0008)
6.03.35F 0006 (ZOT-PS-35/6.3.0006)
6.03.35F 0004 (ZOT-PS-35/6.3.0004)
6.03.35F 0003 (ZOT-PS-35/6.3.0003)

ZO Tech PA301 Parallel Port Print Server
Firmware: 8.03.34F 0019 (ZOT-PS-34/8.3.0019)
8.03.34F 0016 (ZOT-PS-34/8.3.0016)
8.03.34F 0015 (ZOT-PS-34/8.3.0015)
8.03.34F 0011 (ZOT-PS-34/8.3.0011)
8.03.34F 0008 (ZOT-PS-34/8.3.0008)
8.03.34F 0007 (ZOT-PS-34/8.3.0007)

ZO Tech PS531 USB & Parallel Print Server
Firmware: 6.03.39F 0007 (ZOT-PS-39/6.3.0007)
6.03.39F 0006 (ZOT-PS-39/6.3.0006)
6.03.39F 0005 (ZOT-PS-39/6.3.0005)
6.03.39F 0003 (ZOT-PS-39/6.3.0003)

Other versions may also be vulnerable.



[+] Proof of Concept/Exploit

XSS:
http://target/RESTART.HTM?NDSContext=</script><script>alert("xss")</script><script>

and then..

http://target/NETWARE.HTM



[+] Timeline

24-03-2011: first contact to vendor.
03-04-2011: no vendor response.
04-04-2011: advisory published.



[+] References

(1)http://www.zot.com.tw/Product/Product_Detail.asp?ProductID=98
(2)http://www.zot.com.tw/Product/Product_Detail.asp?ProductID=99
(3)http://www.zot.com.tw/Product/Product_Detail.asp?ProductID=118
(4)http://www.zot.com.tw/Product/Product_Detail.asp?ProductID=128



[+] Credits

b0telh0
Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    8 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    11 Files
  • 23
    Apr 23rd
    68 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close