9.3
CVSSv2

CVE-2008-4128

Published: 18/09/2008 Updated: 22/05/2023
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Multiple cross-site request forgery (CSRF) vulnerabilities in the HTTP Administration component in Cisco IOS 12.4 on the 871 Integrated Services Router allow remote malicious users to execute arbitrary commands via (1) a certain "show privilege" command to the /level/15/exec/- URI, and (2) a certain "alias exec" command to the /level/15/exec/-/configure/http URI. NOTE: some of these details are obtained from third party information.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cisco ios 12.4

Exploits

<!-- Jeremy Brown [0xjbrown41@gmailcom/jbrownsecblogspotcom] Cisco Router HTTP Administration CSRF Remote Command Execution Universal Exploit #1 Replace "1010101" with the IP address of the target router, embed this in a web page and hope for the best Cisco Admin's + Safari are the best targets ;) --> <html&gt ...