"Interest in computer security is driven by events, and the number of events is increasing dramatically. - Ralph Merkle"
HIO-2009-0521 Netgear RP614v4 CSRF & XSS PDF Print E-mail

The Netgear RP614v4 Broadband Router exhibits a vulnerabilities which can be exploited by malicious people to conduct cross-site request forgery attacks and cross-site scripting attacks.

1) The application allows users to perform certain actions via HTTP requests without performing any validity checks to verify the request. This can be exploited to e.g. perform all administrative actions by enticing a logged-in administrator to visit a malicious site.

2) Script submitted to /cgi-gin/apply via the AddKeyword variable becomes persistent (script insertion) when submitted by enticing a logged-in administrator to visit a malicious site.

The vulnerability is reported in hardware version 4 and firmware version 1.0.5_04.23. Other versions may also be affected.

References:

CVE-2009-pending

BID: 35214

VUPEN: 

Nessus:N/A

OSVDB: 

SA: 35276  

XF: 

Related: 

Vendor Solution:


 
< Prev   Next >