CVE-2009-2323

The web interface on the Axesstel MV 410R redirects users back to the referring page after execution of some CGI scripts, which makes it easier for remote attackers to avoid detection of cross-site request forgery (CSRF) attacks, as demonstrated by a redirect from the cgi-bin/wireless.cgi script.
Configurations

Configuration 1 (hide)

cpe:2.3:h:axesstel:mv_410r:*:*:*:*:*:*:*:*

History

21 Nov 2024, 01:04

Type Values Removed Values Added
References () http://www.securityfocus.com/archive/1/504716/100/0/threaded - () http://www.securityfocus.com/archive/1/504716/100/0/threaded -
References () http://www.securityfocus.com/bid/35563 - () http://www.securityfocus.com/bid/35563 -

Information

Published : 2009-07-05 16:30

Updated : 2024-11-21 01:04


NVD link : CVE-2009-2323

Mitre link : CVE-2009-2323

CVE.ORG link : CVE-2009-2323


JSON object : View

Products Affected

axesstel

  • mv_410r
CWE
CWE-352

Cross-Site Request Forgery (CSRF)