Skip to content

Instantly share code, notes, and snippets.

@johnkegd
Created August 12, 2021 19:23
Show Gist options
  • Select an option

  • Save johnkegd/62d0773958a870804c555933d5e06034 to your computer and use it in GitHub Desktop.

Select an option

Save johnkegd/62d0773958a870804c555933d5e06034 to your computer and use it in GitHub Desktop.
Exploring vulnerability from Upc router ConnectBox DCHP admin page login
/**
* Exploring Upc Connect Box admin conection vulnerability
* file: base.js
* line: 1026
* @params:
* {@String loginCSRMode} userData.loginCSRMode = "1"
* {@String UserName} userData.UserName = "upccsr"
*/
function getUserData(userData, callback) {
var data;
userData_json = JSON.stringify(userData);
$.ajax({
type: "POST",
url: "php/user_data.php",
data: { userData: userData_json,
opType: "READ" },
dataType: "json",
success: function(msg) {
data = msg;
if(callback) { callback(data); }
},
async:false,
cache:false,
error: function(){
console.log("Falied to get user data");
}
});
return data;
}
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment