cve/2018/CVE-2018-19394.md
2024-06-09 00:33:16 +00:00

860 B

CVE-2018-19394

Description

Cobham Satcom Sailor 800 and 900 devices contained persistent XSS, which required administrative access to exploit. The vulnerability was exploitable by acquiring a copy of the device's configuration file, inserting an XSS payload into a relevant field (e.g., Satellite name), and then restoring the malicious configuration file.

POC

Reference

Github

No PoCs found on GitHub currently.