Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2007-6708

Опубликовано: 13 мар. 2008
Источник: nvd
CVSS2: 4.3
EPSS Низкий

Описание

Multiple cross-site request forgery (CSRF) vulnerabilities on the Cisco Linksys WAG54GS Wireless-G ADSL Gateway with 1.01.03 and earlier firmware allow remote attackers to perform actions as administrators via an arbitrary valid request to an administrative URI, as demonstrated by (1) a Restore Factory Defaults action using the mtenRestore parameter to setup.cgi and (2) creation of a user account using the sysname parameter to setup.cgi.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:h:linksys:wag54gs:*:*:*:*:*:*:*:*
Версия до firmware_1.01.03 (включая)

EPSS

Процентиль: 49%
0.00263
Низкий

4.3 Medium

CVSS2

Дефекты

CWE-352

Связанные уязвимости

github
почти 4 года назад

Multiple cross-site request forgery (CSRF) vulnerabilities on the Cisco Linksys WAG54GS Wireless-G ADSL Gateway with 1.01.03 and earlier firmware allow remote attackers to perform actions as administrators via an arbitrary valid request to an administrative URI, as demonstrated by (1) a Restore Factory Defaults action using the mtenRestore parameter to setup.cgi and (2) creation of a user account using the sysname parameter to setup.cgi.

EPSS

Процентиль: 49%
0.00263
Низкий

4.3 Medium

CVSS2

Дефекты

CWE-352