GotGeek Labs http://www.gotgeek.com.br/ Encore ENPS-2012 Cross-site Scripting Vulnerability [+] Description Encore 3-Port Print Server converts a standalone USB or a parallel printer into a shared printer, through a wired Ethernet connection. As a result, you can save the cost and space for additional printers. ENPS-2012 can connect up to 3 printers - using the 2 USB2.0 ports and 1 parallel port - that users can share across the Internet or local area network (LAN). Printing on the shared printers from anywhere on the Internet is as easy as printing from your own office. For your convenience, ENPS-2012 comes with a friendly WEB-based configuration interface. This device also supports multiple network protocols and operating systems, making shared printing in mixed-LAN environments easy. [+] Information Title: Encore ENPS-2012 Cross-site Scripting Vulnerability Shodan Dork: ZOT-PS-39/6.3.0008 -WWW-Authenticate Advisory: gg-005-2011 Date: 03-15-2011 Last update: 03-26-2011 Link: http://www.gotgeek.com.br/pocs/gg-005-2011.txt [+] Vulnerabilities Stored Cross-site Scripting: Web interface from ENPS-2012 Print Server is affected by stored cross-site scripting vulnerability because it fails to properly sanitize user-supplied input at "NDSContext" field in "NetWare NDS Settings" area. An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. After injecting the XSS code, you need to access Netware status page. XSS: http://target/RESTART.HTM?NDSContext=