PT-2007-6906 · F5 · F5 Firepass 4100 Ssl Vpn

Adrian Pastor

+1

·

Publicado

2007-11-15

·

Atualizado

2018-10-15

·

CVE-2007-5979

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions F5 Firepass 4100 SSL VPN versions 5.4 through 5.5.2 F5 Firepass 4100 SSL VPN versions 6.0 through 6.0.1
Description A cross-site scripting (XSS) issue exists, allowing remote attackers to inject arbitrary web script or HTML via the backurl parameter in the download plugin.php3 file.
Recommendations For versions 5.4 through 5.5.2, avoid using the backurl parameter in the download plugin.php3 file until a fix is available. For versions 6.0 through 6.0.1, restrict access to the download plugin.php3 file to minimize the risk of exploitation.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2007-5979

Produtos afetados

F5 Firepass 4100 Ssl Vpn