D-Link DIR-645 Multiple Buffer Overflow and Cross Site Scripting Vulnerabilities
BID:61579
Info
D-Link DIR-645 Multiple Buffer Overflow and Cross Site Scripting Vulnerabilities
| Bugtraq ID: | 61579 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-7389 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 02 2013 12:00AM |
| Updated: | Jul 08 2014 03:38PM |
| Credit: | Roberto Paleari |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
D-Link DIR-645 Multiple Buffer Overflow and Cross Site Scripting Vulnerabilities
D-Link DIR-645 device is prone to multiple buffer-overflow and cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied input.
Remote attackers can exploit these issues to execute arbitrary code in the context of the affected device or execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and perform unauthorized actions. Other attacks may also be possible.
D-Link DIR-645 running firmware 1.03B08 is vulnerable; other versions may also be affected.
D-Link DIR-645 device is prone to multiple buffer-overflow and cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied input.
Remote attackers can exploit these issues to execute arbitrary code in the context of the affected device or execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and perform unauthorized actions. Other attacks may also be possible.
D-Link DIR-645 running firmware 1.03B08 is vulnerable; other versions may also be affected.
Exploit / POC
D-Link DIR-645 Multiple Buffer Overflow and Cross Site Scripting Vulnerabilities
An attacker can exploit these issues using a web browser. To exploit multiple cross-site scripting issues, an attacker must entice an unsuspecting victim to follow a malicious URI.
The researcher who discovered these issues has created a proof-of-concept. Please see the references for more information.
The following exploits are available:
An attacker can exploit these issues using a web browser. To exploit multiple cross-site scripting issues, an attacker must entice an unsuspecting victim to follow a malicious URI.
The researcher who discovered these issues has created a proof-of-concept. Please see the references for more information.
The following exploits are available:
Solution / Fix
D-Link DIR-645 Multiple Buffer Overflow and Cross Site Scripting Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
D-Link DIR-645 Multiple Buffer Overflow and Cross Site Scripting Vulnerabilities
References:
References: