6.8
CVSSv2

CVE-2013-3095

Published: 20/11/2013 Updated: 20/11/2013
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DIR865L router (Rev. A1) with firmware prior to 1.05b07 allow remote malicious users to hijack the authentication of administrators for requests that (1) change the administrator password or (2) enable remote management via a request to hedwig.cgi or (3) activate configuration changes via a request to pigwidgeon.cgi.

Vulnerable Product Search on Vulmon Subscribe to Product

dlink dir865l_firmware 1.03

dlink dir865l_firmware 1.00b24

dlink dir865l_firmware

dlink dir865l_firmware 1.02

dlink dir865l -

Exploits

source: wwwsecurityfocuscom/bid/59312/info D-Link DIR-865L is prone to a cross-site request-forgery vulnerability Exploiting this issue may allow a remote attacker to perform certain administrative actions and gain unauthorized access to the affected device Other attacks are also possible D-Link DIR-865L firmware version 103 is vuln ...