Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DIR865L router (Rev. A1) with firmware before 1.05b07 allow remote attackers to hijack the authentication of administrators for requests that (1) change the administrator password or (2) enable remote management via a request to hedwig.cgi or (3) activate configuration changes via a request to pigwidgeon.cgi.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2013-11-19T15:00:00Z
Updated: 2024-09-17T02:47:57.440Z
Reserved: 2013-04-17T00:00:00Z
Link: CVE-2013-3095
Vulnrichment
No data.
NVD
Status : Modified
Published: 2013-11-20T13:19:38.913
Modified: 2024-11-21T01:52:59.793
Link: CVE-2013-3095
Redhat
No data.