Ivano Binetti

Personal Blog

Main menu

Skip to primary content
Skip to secondary content
  • Home
  • About Me
  • My Publications
  • Contacts

Daily Archives: February 20, 2012

PlumeCMS <= 1.2.4 CSRF "0day" Vulnerability

Posted on February 20, 2012
Reply

New “0day” vulnerability discovered regarding PluseCMS.

For more details:
http://osvdb.org/show/osvdb/80807
http://www.exploit-db.com/author/?a=3557
http://packetstormsecurity.org/files/author/9536/

Posted in 0day Vulnerabilities, OSVDB, Web Vulnerabilities | Leave a reply

D-Link DSL-2640B (ADSL Router) CSRF "0day" Vulnerability

Posted on February 20, 2012
Reply

I’ve discovered a new “0day” vulnerability:

To view my Original Advisory:
D-Link DSL-2640B CSRF (Change admin Password) Original Advisory

Other related publications:
http://osvdb.org/show/osvdb/80803
http://www.securityfocus.com/bid/52096/info
http://www.exploit-db.com/author/?a=3557
http://packetstormsecurity.org/files/author/9536/

This vulnerability allows to change administrator password of D-Link DSL-2640B ADSL Router.

Posted in 0day Vulnerabilities, hardware, Web Vulnerabilities | Leave a reply
Follow @ivanobinetti

Real Time Tweets

RT @matteorenzi: Oggi Grillo torna al referendum sull'Euro. Grida al colpo di Stato. Da quando ha capito che non andranno a Palazzo Chigi h…
- Friday May 4 - 3:14pm

RT @Veracode: @IvanoBinetti What are the gaps in your appsec program, Ivano? See how you stack up to your peers: http://t.co/m2d7K4jh9X
- Monday Jan 5 - 1:45pm

RT @Breakingviews: #Italy’s lesson for Europe: do your homework http://t.co/3bvzjYYX6c Read @Unmack1 on Matteo Renzi’s European election tr…
- Tuesday May 27 - 1:37pm

D-Link firmware in order to fix my vulnerabilities is coming http://t.co/AMUUxkS3eG #cybersecurity #dlink
- Thursday Mar 13 - 10:44pm

RT @_hkm: Added D-Link DSL-2740B - Disable Wireless MAC Filter http://t.co/Mxl5TWS1J8 by @IvanoBinetti
- Tuesday Mar 4 - 4:17pm

Categories

  • 0day Vulnerabilities
  • Browser
  • Bugtraq ID – Security Focus
  • CVE MITRE
  • ftp
  • Google
  • hardware
  • IBM X-Force
  • Inj3ct0r
  • Javascript
  • Kaspersky Lab
  • Linux bash
  • Metasploit
  • Netcat
  • NIST – NVD
  • OSVDB
  • Packet Storm
  • Perl
  • Secunia
  • Uncategorized
  • web
  • Web Vulnerabilities

Recent Posts

  • Apache Tomcat 5.5.25 Deploy/Undeploy/Start/Stop Applications
  • D-Link DSL-2740B Multiple CSRF Vulnerabilities | CVE-2013-5730
  • Update on Google Translate CSRF Vulnerability | Google is fixing the issue
  • Translate.google.com | CSRF Vulnerability
  • D-Link DSL-2740B (ADSL Router) Authentication Bypass | CVE-2013-2271

Archives

  • November 2013
  • September 2013
  • June 2013
  • March 2013
  • May 2012
  • April 2012
  • March 2012
  • February 2012
  • January 2012
  • October 2011
  • June 2011
  • March 2011
  • January 2011
  • December 2010
  • November 2010
  • October 2010

Calendar

February 2012
M T W T F S S
« Jan   Mar »
 12345
6789101112
13141516171819
20212223242526
272829  
Ivano Binetti @2010-2014