Document Title: =============== Alcatel Lucent Home Device Manager - Management Console Multiple XSS CVE-Number: =========== CVE-2015-8687 Release Date: ============= 03 Jan 2016 Abstract Advisory Information: ============================= Ugur Cihan Koc discovered ten Reflected XSS vulnerabilities Alcatel Lucent Home Device Manager - Management Console Vulnerability Disclosure Timeline: ================================== 10 Dec 2015 Bug reported to the vendor. 10 Dec 2015 Vendor returned ; investigating 16 Dec 2015 Vendor has validated the issues & fixed 27 Dec 2015 CVE number assigned 03 Jan 2016 Disclosured Affected Product(s): ==================== Alcatel Lucent Home Device Manager - Management Console 4.1.10.5 may be old version could be affected Exploitation Technique: ======================= Local, Authenticated Severity Level: =============== High Technical Details & Description: ================================ Ø Sample Payload : 42f8b36