Command Injection vulnerability exists via a CSRF in DD-WRT 24-sp2 from specially crafted configuration values containing shell meta-characters, which could let a remote malicious user cause a Denial of Service.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
https://packetstormsecurity.com/files/cve/CVE-2012-6297 | vdb entry third party advisory |
https://vuldb.com/?id.9527 | permissions required |
https://seclists.org/fulldisclosure/2013/Oct/241 | third party advisory mailing list |
https://lists.openwall.net/bugtraq/2013/07/12/2 | third party advisory mailing list |