Linksys WRT110 Cross Site Request Forgery and Command Injection Vulnerabilities
BID:61151
CVE-2013-3568 |Info
Linksys WRT110 Cross Site Request Forgery and Command Injection Vulnerabilities
| Bugtraq ID: | 61151 |
| Class: | Unknown |
| CVE: |
CVE-2013-3568 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 12 2013 12:00AM |
| Updated: | Sep 21 2013 12:15AM |
| Credit: | Craig Young |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Linksys WRT110 Cross Site Request Forgery and Command Injection Vulnerabilities
Linksys WRT110 is prone to cross-site request-forgery and command-injection vulnerabilities.
Exploiting these issues may allow a remote attacker to perform certain administrative actions and execute arbitrary shell commands with root privileges. Other attacks are also possible.
Linksys WRT110 is prone to cross-site request-forgery and command-injection vulnerabilities.
Exploiting these issues may allow a remote attacker to perform certain administrative actions and execute arbitrary shell commands with root privileges. Other attacks are also possible.
Exploit / POC
Linksys WRT110 Cross Site Request Forgery and Command Injection Vulnerabilities
To exploit the cross-site request-forgery issue, an attacker must entice an unsuspecting victim into following a malicious URI. The attacker can exploit the command-injection issue using a web browser.
The following exploit is available:
To exploit the cross-site request-forgery issue, an attacker must entice an unsuspecting victim into following a malicious URI. The attacker can exploit the command-injection issue using a web browser.
The following exploit is available:
Solution / Fix
Linksys WRT110 Cross Site Request Forgery and Command Injection Vulnerabilities
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Linksys WRT110 Cross Site Request Forgery and Command Injection Vulnerabilities
References:
References:
- Linksys Homepage (Linksys)