Web Hack List

Collected research

DHCP Script Injection

usefulfor.com/security » Blog Archive » DHCP Script Injection

A DHCPREQUEST whose Options Hostname field carries HTML or script is stored by the DHCP server and executed when an administrator opens the active-leases page of a router's web admin interface. The injected iframe loads attacker JavaScript that auto-submits a CSRF POST to exec.php and runs shell commands. Demonstrated against pfSense, with tool and advisory.

Record

Document
usefulfor.com/security » Blog Archive » DHCP Script Injection
Published by
usefulfor.com
Topic
XSS

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of usefulfor.com, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .