Bugtraq mailing list archives

Re: Linksys Cisco Wag120N CSRF Vulnerability


From: tadeu1 () gmail com
Date: Fri, 25 Feb 2011 13:01:28 -0700

I would like to recommend to people who want to test the code to disable/wipe out unnecessary options such as 
"remote_management" and "http_wanport" since they could give eventual outside attacker chances of authentication.

Another doubt lies on the possibility that this code implictly relies on a previous form of authentication for being 
effective.


Current thread: