Record summary

CVE-2012-5319 has a selected CVSS score of 6.8; EIP currently links 2 catalogued exploits.

Description

Cross-site request forgery (CSRF) vulnerability in setup/security.cgi in D-Link DCS-900, DCS-2000, and DCS-5300 allows remote attackers to hijack the authentication of administrators for requests that change the administrator password via the rootpass parameter.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
2

Proofs of concept

2

Catalogued exploits

ExploitDBD-Link DCS Series - Cross-Site Request Forgery (Change Admin Password)ExploitDB exploitby riganNot analyzed1 file
ExploitDB

PoC details
ExploitDBD-Link DCS - 'security.cgi' Cross-Site Request ForgeryExploitDB exploitby Rigan IimriganNot analyzed1 file
ExploitDB

PoC details

References

3