m0n0wall Multiple Cross Site Request Forgery Vulnerabilities
BID:56844
Info
m0n0wall Multiple Cross Site Request Forgery Vulnerabilities
| Bugtraq ID: | 56844 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 06 2012 12:00AM |
| Updated: | Dec 06 2012 12:00AM |
| Credit: | Yann CAM of Synetis |
| Vulnerable: |
Manuel Kasper m0n0wall 1.33 |
| Not Vulnerable: |
Manuel Kasper m0n0wall 1.34 |
Discussion
m0n0wall Multiple Cross Site Request Forgery Vulnerabilities
m0n0wall is prone to multiple cross-site request-forgery vulnerabilities because it fails to properly validate POST requests.
Attackers can exploit these issues to perform certain administrative actions and gain unauthorized access to the affected application. Other attacks are also possible.
m0n0wall 1.33 is vulnerable; other versions may also be affected.
m0n0wall is prone to multiple cross-site request-forgery vulnerabilities because it fails to properly validate POST requests.
Attackers can exploit these issues to perform certain administrative actions and gain unauthorized access to the affected application. Other attacks are also possible.
m0n0wall 1.33 is vulnerable; other versions may also be affected.
Exploit / POC
m0n0wall Multiple Cross Site Request Forgery Vulnerabilities
An attacker can exploit these issues by enticing an unsuspecting victim to follow a malicious URI.
The following exploit codes are available:
An attacker can exploit these issues by enticing an unsuspecting victim to follow a malicious URI.
The following exploit codes are available:
Solution / Fix
m0n0wall Multiple Cross Site Request Forgery Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
m0n0wall Multiple Cross Site Request Forgery Vulnerabilities
References:
References:
- m0n0wall 1.34 Changelog (Manuel Kasper)
- m0n0wall Homepage (Manuel Kasper)