CVE-2008-4128
Cisco Router - HTTP Administration Cross-Site Request Forgery / Command Execution
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
3Exploited in Wild
-Decision
Descriptions
Multiple cross-site request forgery (CSRF) vulnerabilities in the HTTP Administration component in Cisco IOS 12.4 on the 871 Integrated Services Router allow remote attackers to execute arbitrary commands via (1) a certain "show privilege" command to the /level/15/exec/- URI, and (2) a certain "alias exec" command to the /level/15/exec/-/configure/http URI. NOTE: some of these details are obtained from third party information.
Vulnerabilidad múltiple de falsificación de petición en sitios cruzados - CSRF en el componente de administración HTTP en el IOS Cisco 12.4 en el Router de Servicios Integrados 871, que permite a los atacantes remotos ejecutar arbitrariamente comandos a través de(1) ciertos comandos que "muestran lo privilegios" en /level/15/exec/- URI, y (2) ciertos comandos "alias exec" en /level/15/exec/-/configure/http URI. NOTA: algunos de estos detalles fueron obtenidos de información de terceros.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2008-09-18 CVE Reserved
- 2008-09-18 CVE Published
- 2024-03-29 EPSS Updated
- 2024-08-07 CVE Updated
- 2024-08-07 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-352: Cross-Site Request Forgery (CSRF)
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
http://jbrownsec.blogspot.com/2008/09/cisco-0day-released.html | Broken Link | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/45226 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/6476 | 2024-08-07 | |
http://www.securityfocus.com/bid/31218 | 2024-08-07 | |
https://www.exploit-db.com/exploits/6477 | 2024-08-07 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Ios Search vendor "Cisco" for product "Ios" | 12.4 Search vendor "Cisco" for product "Ios" and version "12.4" | - |
Affected
| in | Cisco Search vendor "Cisco" | 871 Integrated Services Router Search vendor "Cisco" for product "871 Integrated Services Router" | - | - |
Safe
|