CVE-2011-5284

Smoothwall < 3.1 - Cross-Site Request Forgery via shutdown.cgi

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2011-5284. PoCs published by dave b.

AI-analyzed exploit summary The exploit demonstrates XSS and CSRF vulnerabilities in SmoothWall Express 3.0's web management interface. The XSS payload injects a script via the 'IP' parameter, while the CSRF example forces a reboot action without user interaction.

Description

Cross-site request forgery (CSRF) vulnerability in the web management interface in httpd/cgi-bin/shutdown.cgi in Smoothwall Express 3.1 and 3.0 SP3 and earlier allows remote attackers to hijack the authentication of administrators for requests that perform a reboot via a request to cgi-bin/shutdown.cgi.

Exploits (1)

exploitdb WORKING POC
by dave b · htmlwebappscgi
https://www.exploit-db.com/exploits/16006

The exploit demonstrates XSS and CSRF vulnerabilities in SmoothWall Express 3.0's web management interface. The XSS payload injects a script via the 'IP' parameter, while the CSRF example forces a reboot action without user interaction.

Classification
Working Poc 100%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: SmoothWall Express 3.0
No auth needed
Prerequisites: Network access to the SmoothWall web interface · Victim interaction for XSS (auto-submit script mitigates this)
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/show/osvdb/70497
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/99403
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/16006

Scores

EPSS 0.0227
EPSS Percentile 80.7%

Details

CWE
CWE-352
Status published
Products (2)
smoothwall/smoothwall 3.0 sp3
smoothwall/smoothwall < 3.1
Published Dec 31, 2014
Tracked Since Feb 18, 2026