A-Link WL54AP3 and WL54AP2 Cross Site Request Forgery and HTML Injection Vulnerabilities
BID:32008
Info
A-Link WL54AP3 and WL54AP2 Cross Site Request Forgery and HTML Injection Vulnerabilities
| Bugtraq ID: | 32008 |
| Class: | Unknown |
| CVE: |
CVE-2008-6823 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 31 2008 12:00AM |
| Updated: | Apr 16 2015 05:52PM |
| Credit: | Jussi Vuokko and Henri Lindberg |
| Vulnerable: |
A-Link WL54AP3 0 A-Link WL54AP2 0 |
| Not Vulnerable: | |
Discussion
A-Link WL54AP3 and WL54AP2 Cross Site Request Forgery and HTML Injection Vulnerabilities
A-Link WL54AP3 and WL54AP2 are prone to a cross-site request-forgery vulnerability and an HTML-injection vulnerability.
An attacker can exploit the cross-site request-forgery issue to alter the administrative configuration on affected devices. This may lead to further network-based attacks.
The attacker can exploit the HTML-injection issue to execute arbitrary script code in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
A-Link WL54AP3 and WL54AP2 are prone to a cross-site request-forgery vulnerability and an HTML-injection vulnerability.
An attacker can exploit the cross-site request-forgery issue to alter the administrative configuration on affected devices. This may lead to further network-based attacks.
The attacker can exploit the HTML-injection issue to execute arbitrary script code in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
Exploit / POC
A-Link WL54AP3 and WL54AP2 Cross Site Request Forgery and HTML Injection Vulnerabilities
To exploit the cross-site request-forgery issue, an attacker must entice an unsuspecting victim into following a malicious URI. The attacker can exploit the HTML-injection issue through a browser.
The following exploit code is available:
To exploit the cross-site request-forgery issue, an attacker must entice an unsuspecting victim into following a malicious URI. The attacker can exploit the HTML-injection issue through a browser.
The following exploit code is available:
Solution / Fix
A-Link WL54AP3 and WL54AP2 Cross Site Request Forgery and HTML Injection Vulnerabilities
Solution:
The vendor released an update to address these issues. Please see the references for more information.
Solution:
The vendor released an update to address these issues. Please see the references for more information.
References
A-Link WL54AP3 and WL54AP2 Cross Site Request Forgery and HTML Injection Vulnerabilities
References:
References:
- A-Link WL54AP3 and WL54AP2 CSRF+XSS vulnerability (Jussi Vuokko and Henri Lindberg)
- Vendor Homepage (A-Link)
- A-Link WL54AP3 and WL54AP2 CSRF+XSS vulnerability (Henri Lindberg - Smilehouse Oy
)