D-Link DSL-504T allows remote attackers to bypass authentication and gain privileges, such as upgrade firmware, restart the router or restore a saved configuration, via a direct request to firmwarecfg.
The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.
Link | Tags |
---|---|
http://secunia.com/advisories/15422 | third party advisory broken link |
http://marc.info/?l=bugtraq&m=111722515805478&w=2 | third party advisory mailing list |
http://www.securityfocus.com/bid/13679 | vdb entry third party advisory broken link |