NetGear RAIDiator Cross Site Request Forgery and Command Injection Vulnerabilities
BID:62059
Info
NetGear RAIDiator Cross Site Request Forgery and Command Injection Vulnerabilities
| Bugtraq ID: | 62059 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-2751 CVE-2013-2752 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 05 2013 12:00AM |
| Updated: | Nov 26 2013 07:56AM |
| Credit: | Craig Young |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
NetGear RAIDiator Cross Site Request Forgery and Command Injection Vulnerabilities
NetGear RAIDiator is prone to a cross-site request-forgery vulnerability and a command-injection vulnerability.
Exploiting these issues may allow a remote attacker to perform certain administrative actions and execute arbitrary shell commands with root privileges. Other attacks are also possible.
Following are vulnerable:
RAIDiator versions prior to 4.1.12 running on SPARC
RAIDiator-x86 versions prior to 4.2.24
NetGear RAIDiator is prone to a cross-site request-forgery vulnerability and a command-injection vulnerability.
Exploiting these issues may allow a remote attacker to perform certain administrative actions and execute arbitrary shell commands with root privileges. Other attacks are also possible.
Following are vulnerable:
RAIDiator versions prior to 4.1.12 running on SPARC
RAIDiator-x86 versions prior to 4.2.24
Exploit / POC
NetGear RAIDiator Cross Site Request Forgery and Command Injection Vulnerabilities
To exploit the cross-site request-forgery issue, an attacker must entice an unsuspecting victim into following a malicious URI. The attacker can exploit the command-injection issue using a web browser.
The following exploits are available:
To exploit the cross-site request-forgery issue, an attacker must entice an unsuspecting victim into following a malicious URI. The attacker can exploit the command-injection issue using a web browser.
The following exploits are available:
Solution / Fix
NetGear RAIDiator Cross Site Request Forgery and Command Injection Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
NetGear RAIDiator Cross Site Request Forgery and Command Injection Vulnerabilities
References:
References:
- Netgear Homepage (NetGear)