Hillstone Next Generation FireWall XSS(CVE-2023-46964)
Discoverer:NHPT
Introduce
The next generation firewall of Shanshi Network Technology is an intrusion prevention technology based on deep application, protocol detection, and attack principle analysis. It can effectively filter out security threats such as viruses, trojans, worms, spyware, vulnerability attacks, and escape attacks, providing users with comprehensive security protection of L2-L7 layer networks, while effectively protecting user network health and server security, and providing excellent security protection performance; Through deep detection and analysis technology of network traffic, multi-dimensional accurate identification can be carried out based on applications, users, content, national geography, etc., providing users with rich and flexible security control functions; Through strong network adaptability, it can achieve secure deployment in complex environments and meet the diverse network functional needs of users.
Vendor of the product(s)
https://www.hillstonenet.com.cn/
Product
Hillstone Next Generation FireWall SG-6000-E3960
Version 5.5
Vulnerability Description
Hillstone Next Generation FireWall hostname has an XSS vulnerability due to the use of front-end filtering instead of back-end filtering.
Principle and recurrence of vulnerabilities
The device information with vulnerabilities is as follows:
{cat_hide}
Modify the host name in the browser:
Then use Burp to intercept the data packet and insert Payload:<img src='<http://127.0.0.1/a.js>' onerror=alert(1)>
Trigger XSS vulnerability when viewing system information:
{/cat_hide}
最后更新于 2026-08-14 「部分内容存在时效性,如有失效请留言反馈」
除注明外为 Hack All Sec 的博客 原创文章,转载请注明出处。
本作品采用 知识共享署名-相同方式共享 4.0 国际许可协议 进行许可。
Hack All Sec 的博客