[<prev] [next>] [day] [month] [year] [list]
Message-Id: <200812110214.mBB2EA2i016231@www5.securityfocus.com>
Date: Wed, 10 Dec 2008 19:14:10 -0700
From: dan.crowley@...il.com
To: bugtraq@...urityfocus.com
Subject: Re: Multiple XSRF in DD-WRT (Remote Root Command Execution)
This doesn't look like an XRSF flaw to me, unless this html is supposed to be inserted via some XRSF flaw, in which case you've given us a payload with no vulnerability details and no PoC exploit.
Looks like someone from the DD-WRT team has also commented, denying that this is actually a vulnerability.
If you have more details, please do post them.
Powered by blists - more mailing lists