CVE-2009-1561

Cross-site request forgery (CSRF) vulnerability in administration.cgi on the Cisco Linksys WRT54GC router with firmware 1.05.7 allows remote attackers to hijack the intranet connectivity of arbitrary users for requests that change the administrator password via the sysPasswd and sysConfirmPasswd parameters.
Configurations

Configuration 1 (hide)

cpe:2.3:h:cisco:wrt54gc:1.05.7:*:*:*:*:*:*:*

History

21 Nov 2024, 01:02

Type Values Removed Values Added
References () http://archives.neohapsis.com/archives/bugtraq/2009-04/0198.html - () http://archives.neohapsis.com/archives/bugtraq/2009-04/0198.html -
References () http://packetstormsecurity.org/0904-exploits/linksysadmin-passwd.txt - Exploit () http://packetstormsecurity.org/0904-exploits/linksysadmin-passwd.txt - Exploit
References () http://secunia.com/advisories/34805 - Vendor Advisory () http://secunia.com/advisories/34805 - Vendor Advisory
References () http://www.falandodeseguranca.com/?p=17 - () http://www.falandodeseguranca.com/?p=17 -
References () http://www.securityfocus.com/bid/34616 - Exploit () http://www.securityfocus.com/bid/34616 - Exploit
References () http://www.vupen.com/english/advisories/2009/1172 - Vendor Advisory () http://www.vupen.com/english/advisories/2009/1172 - Vendor Advisory

Information

Published : 2009-05-06 16:30

Updated : 2024-11-21 01:02


NVD link : CVE-2009-1561

Mitre link : CVE-2009-1561

CVE.ORG link : CVE-2009-1561


JSON object : View

Products Affected

cisco

  • wrt54gc
CWE
CWE-352

Cross-Site Request Forgery (CSRF)